SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/infoplugin.php involving the $plugin parameter, as demonstrated by a /ecrire/?exec=infoplugin URL.
$plugin
{ "binaries": [ { "binary_name": "spip", "binary_version": "3.0.21-1ubuntu1" } ] }