CVE-2025-71241: SPIP < 4.3.6 Cross-Site Scripting in Private Area
Published Feb 19, 2026
·Updated
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the SPIP security screen.
Affected Software
4 affected components
Spip SPIP<4.3.6
Spip SPIP>=4.1.0<4.1.20
Spip SPIP>=4.2.0<4.2.17
Spip SPIP>=4.3.0<4.3.6
Event History
Feb 19, 2026
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:27 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71241?
CVE-2025-71241 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-71241?
To fix CVE-2025-71241, update SPIP to version 4.3.6 or later.
3
Who is affected by CVE-2025-71241?
CVE-2025-71241 affects users of SPIP versions earlier than 4.3.6, including 4.2.17 and 4.1.20.
4
What type of vulnerability is CVE-2025-71241?
CVE-2025-71241 is a Cross-Site Scripting (XSS) vulnerability found in the private area of SPIP.
5
What impact does CVE-2025-71241 have on users?
CVE-2025-71241 allows attackers to inject malicious scripts, which can compromise user data and security.