Back

CVE-2006-0518

Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

Published: Feb 2, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
spip spip *
spip spip *

GitHub Security Advisory GHSA-4hxq-fhr5-rx6m

Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 3.91%

Top 11% most likely to be exploited

Threat Score 18.4 / 100

Data Sources

NVD EPSS GitHub