296,213
Total vulnerabilities in the database
ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
Software | From | Fixed in |
---|---|---|
spip / spip | 4.2.0 | 4.2.7 |
spip / spip | - | 4.1.13 |