VYPR

Spip

by Spip

Source repositories

CVEs (79)

  • CVE-2022-28960HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.02

    A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

  • CVE-2022-26846HigMar 10, 2022
    risk 0.57cvss 8.8epss 0.03

    SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

  • CVE-2021-44123HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.02

    SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

  • CVE-2021-44122HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.00

    SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is…

  • CVE-2019-11071HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.03

    SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.

  • CVE-2026-8430HigMay 12, 2026
    risk 0.53cvss 8.1epss 0.00

    SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through…

  • CVE-2026-27475HigFeb 19, 2026
    risk 0.53cvss 8.1epss 0.01

    SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can…

  • CVE-2016-7982HigJan 18, 2017
    risk 0.53cvss 7.5epss 0.21

    Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.

  • CVE-2026-22205HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and…

  • CVE-2016-7999HigJan 18, 2017
    risk 0.48cvss 7.4epss 0.02

    ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.

  • CVE-2026-33549MedMar 22, 2026
    risk 0.44cvss 6.7epss 0.00

    SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

  • CVE-2026-27473MedFeb 19, 2026
    risk 0.42cvss 6.4epss 0.00

    SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts…

  • CVE-2025-71242MedFeb 19, 2026
    risk 0.42cvss 6.5epss 0.00

    SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to…

  • CVE-2019-19830MedDec 17, 2019
    risk 0.42cvss 6.5epss 0.01

    _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.

  • CVE-2019-16391MedSep 17, 2019
    risk 0.42cvss 6.5epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.

  • CVE-2024-53619MedNov 26, 2024
    risk 0.41cvss 6.3epss 0.01

    An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2026-27746MedFeb 25, 2026
    risk 0.40cvss 6.1epss 0.00

    The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary…

  • CVE-2026-27474MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious…

  • CVE-2026-26223MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox…

  • CVE-2025-71244MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login…