Vulnerability Details CVE-2026-26223
SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in the private area. This vulnerability is not mitigated by the SPIP security screen.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.4%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-26223
-
cpe:2.3:a:spip:spip:4.4.0
-
cpe:2.3:a:spip:spip:4.4.1
-
cpe:2.3:a:spip:spip:4.4.2
-
cpe:2.3:a:spip:spip:4.4.3
-
cpe:2.3:a:spip:spip:4.4.4
-
cpe:2.3:a:spip:spip:4.4.5
-
cpe:2.3:a:spip:spip:4.4.6
-
cpe:2.3:a:spip:spip:4.4.7