Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 31 Dec 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:spip:spip:4.1.10:*:*:*:*:*:*:* |
Thu, 18 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spip
Spip spip |
|
| Vendors & Products |
Spip
Spip spip |
Tue, 16 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering. | |
| Title | Spip 4.1.10 Admin Account Spoofing via Malicious SVG Upload | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:07:23.542Z
Reserved: 2025-12-16T00:10:40.314Z
Link: CVE-2023-53900
Updated: 2025-12-16T21:45:09.739Z
Status : Analyzed
Published: 2025-12-16T18:16:07.063
Modified: 2026-04-29T01:00:01.613
Link: CVE-2023-53900
No data.
OpenCVE Enrichment
Updated: 2025-12-16T20:45:01Z