Vulnerability Description
SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spip | Spip | >= 4.2.0, < 4.2.15 |
Related Weaknesses (CWE)
References
- https://blog.spip.net/Mise-a-jour-de-maintenance-et-securite-sortie-de-SPIP-4-2-Release Notes
- https://git.spip.net/spip/spipProduct
- https://www.vulncheck.com/advisories/spip-cross-site-scripting-via-code-tagsThird Party Advisory
FAQ
What is CVE-2025-71240?
CVE-2025-71240 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicio...
How severe is CVE-2025-71240?
CVE-2025-71240 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71240?
Check the references section above for vendor advisories and patch information. Affected products include: Spip Spip.