CVE-2026-27473: SPIP < 4.4.9 Stored Cross-Site Scripting via Syndicated Sites
SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URLSYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts that execute when other administrators view the syndicated site details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27473?
CVE-2026-27473 is classified as a moderate severity vulnerability due to its potential for allowing Stored Cross-Site Scripting (XSS).
How do I fix CVE-2026-27473?
To fix CVE-2026-27473, upgrade to SPIP version 4.4.9 or later, where the XSS vulnerability is addressed.
Who is affected by CVE-2026-27473?
SPIP versions prior to 4.4.9 are affected by CVE-2026-27473, specifically in regards to the private area syndication features.
What type of vulnerability is CVE-2026-27473?
CVE-2026-27473 is a Stored Cross-Site Scripting (XSS) vulnerability that allows for script injection via malicious syndication URLs.
What are the potential impacts of CVE-2026-27473?
The potential impacts of CVE-2026-27473 include executing unauthorized scripts in the contexts of other users' sessions, which can lead to data theft or session hijacking.