CVE-2019-16391: Medium severity Spip SPIP vulnerability
Last updated 26 August 2025
Other sources
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiseraction.php.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16391?
The severity of CVE-2019-16391 is medium with a CVSS score of 6.5.
How can authenticated visitors modify content in SPIP before version 3.1.11 and 3.2 before 3.2.5?
Authenticated visitors can modify any published content in SPIP before version 3.1.11 and 3.2 before 3.2.5 by exploiting vulnerabilities in ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
Which versions of SPIP are affected by CVE-2019-16391?
Versions of SPIP before 3.1.11 and 3.2 before 3.2.5 are affected by CVE-2019-16391.
How can I fix CVE-2019-16391?
To fix CVE-2019-16391, update SPIP to version 3.1.11 or 3.2.5.
Where can I find more information about CVE-2019-16391?
You can find more information about CVE-2019-16391 on the SPIP blog and the SPIP git repository.