CVE-2019-16392: XSS
Published Sep 17, 2019
·Updated
Last updated 26 August 2025
Other sources
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
— Launchpad
Affected Software
7 affected componentsFixes available
Spip SPIP<3.1.11
Spip SPIP>=3.2.0<3.2.5
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/spip
3.2.11-3+deb11u103.2.11-3+deb11u74.4.3+dfsg-1+deb13u14.4.8+dfsg-14.4.9+dfsg-1
Remediation
Event History
Sep 17, 2019
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:22 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·09:30 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:30 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SPIP vulnerability?
The vulnerability ID for this SPIP vulnerability is CVE-2019-16392.
2
What is the severity of CVE-2019-16392?
The severity of CVE-2019-16392 is medium with a CVSS score of 6.1.
3
How does CVE-2019-16392 affect SPIP?
CVE-2019-16392 allows XSS attacks in SPIP versions before 3.1.11 and 3.2 before 3.2.5 through error messages in the prive/formulaires/login.php script.
4
What software versions are affected by CVE-2019-16392?
SPIP versions before 3.1.11 and 3.2 before 3.2.5 are affected by CVE-2019-16392.
5
How can I fix CVE-2019-16392 in SPIP?
To fix CVE-2019-16392, update SPIP to version 3.1.11 or 3.2.5.