Skip to main content
Loading…
    CVE-2026-26223 — SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an at — CVE Database · The Intelligence Room