SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/pucestatut.php involving the $id parameter, as demonstrated by a /ecrire/?exec=pucestatut URL.
$id
{ "binaries": [ { "binary_name": "spip", "binary_version": "3.0.21-1ubuntu1" } ] }