CVE-2025-71248: XSS
Published Feb 19, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Spip SPIP<4.4.9
Event History
Feb 19, 2026
CVE Published
via MITRE·02:58 PM
Rejected
via MITRE·02:58 PM
Data Sourced
via NVD·04:27 PM
Description
Rejected
via MITRE·06:38 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-71248?
CVE-2025-71248 has a moderate severity level as it allows Stored Cross-Site Scripting vulnerabilities in SPIP.
2
How do I fix CVE-2025-71248?
To fix CVE-2025-71248, upgrade SPIP to version 4.4.9 or later to ensure proper sanitization of the #URL_SYNDIC output.
3
Who is affected by CVE-2025-71248?
CVE-2025-71248 affects all versions of SPIP prior to 4.4.9 that utilize the syndicated sites feature.
4
Can CVE-2025-71248 be exploited remotely?
Yes, CVE-2025-71248 can be exploited remotely by an attacker able to inject a malicious syndication URL.
5
What type of vulnerability is CVE-2025-71248?
CVE-2025-71248 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the private area of SPIP.