CVE-2025-71240
SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.
Vendor
Product
CWE
Yayın Tarihi
2026-02-19 16:27:11
Güncelleme
2026-02-24 18:53:21
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-