CVE-2025-71244: SPIP < 4.4.5 Open Redirect via Login Form

Published Feb 19, 2026
·
Updated

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.

Affected Software

4 affected components
Spip SPIP<4.4.5
Spip SPIP<4.3.9
Spip SPIP>=4.3.0<4.3.9
Spip SPIP>=4.4.0<4.4.5

Event History

Feb 19, 2026
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:27 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-71244?

The severity of CVE-2025-71244 is classified as a medium risk due to the potential for phishing and exploitation via open redirects.

2

How do I fix CVE-2025-71244?

To fix CVE-2025-71244, update your SPIP installation to version 4.4.5 or later, or 4.3.9 if using that branch.

3

What type of vulnerability is CVE-2025-71244?

CVE-2025-71244 is an open redirect vulnerability that allows attackers to redirect users to arbitrary external sites.

4

Which versions of SPIP are affected by CVE-2025-71244?

CVE-2025-71244 affects SPIP versions prior to 4.4.5 and 4.3.9.

5

What can attackers do with CVE-2025-71244?

Attackers can use CVE-2025-71244 to perform phishing attacks by redirecting users to malicious sites after login.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203