CVE-2025-71242 - SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure

CVE-2025-71242 - SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure

CVE ID : CVE-2025-71242 Published : Feb. 19, 2026, 4:27 p.m. | 11 minutes ago Description : SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted content. This vulnerability is not mitigated by the SPIP security screen. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Feb. 19, 2026