CVE-2016-9998
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.
Date published : 2016-12-16
http://www.securityfocus.com/bid/95008
https://core.spip.net/projects/spip/repository/revisions/23288
