CVE-2019-16394: Medium severity Spip SPIP vulnerability
Last updated 26 August 2025
Other sources
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16394?
CVE-2019-16394 is a vulnerability in SPIP before 3.1.11 and 3.2 before 3.2.5 that provides different error messages from the password-reminder page.
How does CVE-2019-16394 affect SPIP?
CVE-2019-16394 allows attackers to enumerate subscribers by exploiting the different error messages from the password-reminder page.
What is the severity of CVE-2019-16394?
The severity of CVE-2019-16394 is medium with a CVSS score of 5.3.
What is the recommended remedy for CVE-2019-16394?
The recommended remedy for CVE-2019-16394 is to update SPIP to version 3.1.11 or 3.2.5.
Where can I find more information about CVE-2019-16394?
You can find more information about CVE-2019-16394 at the following references: [link1], [link2], [link3].