Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27746

Опубликовано: 25 фев. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary script content into pages that render a jeux block. When a victim is induced to visit a crafted URL, the injected content is reflected into the response and executed in the victim's browser context.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:spip:jeux:*:*:*:*:*:*:*:*
Версия до 4.1.1 (исключая)

EPSS

Процентиль: 10%
0.00201
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
4 месяца назад

The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary script content into pages that render a jeux block. When a victim is induced to visit a crafted URL, the injected content is reflected into the response and executed in the victim's browser context.

EPSS

Процентиль: 10%
0.00201
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79