CVE-2025-71248

CVSS

No CVSS.

R

ejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

References

No reference.

Configurations

No configuration.

History

19 Feb 2026, 19:22

Type Values Removed Values Added
CWE CWE-79
Summary (en) SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts that execute when other administrators view the syndicated site details. (en) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : unknown
References
  • {'url': 'https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-9.html', 'source': '[email protected]'}
  • {'url': 'https://git.spip.net/spip/spip', 'source': '[email protected]'}
  • {'url': 'https://www.vulncheck.com/advisories/spip-stored-cross-site-scripting-via-syndicated-sites', 'source': '[email protected]'}

19 Feb 2026, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 16:27

Updated : 2026-02-19 19:22


NVD link : CVE-2025-71248

Mitre link : CVE-2025-71248

CVE.ORG link : CVE-2025-71248


JSON object : View

Products Affected

No product.

CWE

No CWE.