VYPR

Interface Traduction Objets

by Spip

CVEs (2)

  • CVE-2026-27747HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.00

    The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability in interface_traduction_objets_pipelines.php. When handling translation requests, the plugin reads the id_parent parameter from user-supplied input and…

  • CVE-2026-27745HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.01

    The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output…