VYPR

Referer Spam

by Spip

CVEs (1)

  • CVE-2026-27743CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE…