VYPR

Vendor CVEs

Spip

All CVEs

80 total · sorted by risk
  • CVE-2023-27372CriFeb 28, 2023
    risk 0.75cvss 9.8epss 1.00

    SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

  • CVE-2024-8517CriSep 6, 2024
    risk 0.74cvss 9.8epss 0.95

    SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

  • CVE-2024-7954CriAug 23, 2024
    risk 0.74cvss 9.8epss 0.90

    The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

  • CVE-2025-71243CriFeb 19, 2026
    risk 0.67cvss 9.8epss 0.05

    The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version…

  • CVE-2026-27744CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered…

  • CVE-2026-27743CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE…

  • CVE-2023-24258CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2020-28984CriNov 23, 2020
    risk 0.64cvss 9.8epss 0.02

    prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.

  • CVE-2017-9736CriJun 17, 2017
    risk 0.64cvss 9.8epss 0.03

    SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.

  • CVE-2016-3154CriApr 8, 2016
    risk 0.64cvss 9.8epss 0.02

    The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.

  • CVE-2016-3153CriApr 8, 2016
    risk 0.64cvss 9.8epss 0.02

    SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.

  • CVE-2016-7998HigJan 18, 2017
    risk 0.61cvss 8.8epss 0.14

    The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.

  • CVE-2016-7980HigJan 18, 2017
    risk 0.61cvss 8.8epss 0.04

    Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE:…

  • CVE-2022-37155HigDec 14, 2022
    risk 0.60cvss 8.8epss 0.40

    RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

  • CVE-2026-66738HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when…

  • CVE-2026-8429HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.01

    SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability to achieve code execution that bypasses the SPIP security…

  • CVE-2026-22206HigFeb 26, 2026
    risk 0.57cvss 8.8epss 0.01

    SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to…

  • CVE-2026-27747HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.00

    The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability in interface_traduction_objets_pipelines.php. When handling translation requests, the plugin reads the id_parent parameter from user-supplied input and…

  • CVE-2026-27745HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.01

    The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output…

  • CVE-2023-53900HigDec 16, 2025
    risk 0.57cvss 8.8epss 0.00

    Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload…

  • CVE-2022-28961HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.02

    Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters.

  • CVE-2022-28960HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.02

    A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

  • CVE-2022-26846HigMar 10, 2022
    risk 0.57cvss 8.8epss 0.03

    SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

  • CVE-2021-44123HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.02

    SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

  • CVE-2021-44122HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.00

    SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is…

  • CVE-2019-11071HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.03

    SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.

  • CVE-2026-8430HigMay 12, 2026
    risk 0.53cvss 8.1epss 0.00

    SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through…

  • CVE-2026-27475HigFeb 19, 2026
    risk 0.53cvss 8.1epss 0.01

    SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can…

  • CVE-2016-7982HigJan 18, 2017
    risk 0.53cvss 7.5epss 0.21

    Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.

  • CVE-2026-22205HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and…

  • CVE-2016-7999HigJan 18, 2017
    risk 0.48cvss 7.4epss 0.02

    ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.

  • CVE-2026-33549MedMar 22, 2026
    risk 0.44cvss 6.7epss 0.00

    SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

  • CVE-2026-27473MedFeb 19, 2026
    risk 0.42cvss 6.4epss 0.00

    SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts…

  • CVE-2025-71242MedFeb 19, 2026
    risk 0.42cvss 6.5epss 0.00

    SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to…

  • CVE-2019-19830MedDec 17, 2019
    risk 0.42cvss 6.5epss 0.01

    _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.

  • CVE-2019-16391MedSep 17, 2019
    risk 0.42cvss 6.5epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.

  • CVE-2024-53619MedNov 26, 2024
    risk 0.41cvss 6.3epss 0.01

    An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2026-27746MedFeb 25, 2026
    risk 0.40cvss 6.1epss 0.00

    The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary…

  • CVE-2026-27474MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious…

  • CVE-2026-26223MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox…

  • CVE-2025-71244MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login…

  • CVE-2025-71241MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the…

  • CVE-2024-23659MedJan 19, 2024
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

  • CVE-2023-52322MedJan 4, 2024
    risk 0.40cvss 6.1epss 0.00

    ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

  • CVE-2022-28959MedMay 19, 2022
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.

  • CVE-2019-16393MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

  • CVE-2019-16392MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.

  • CVE-2017-15736MedOct 22, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.

  • CVE-2016-7981MedJan 18, 2017
    risk 0.40cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

  • CVE-2016-9998MedDec 17, 2016
    risk 0.40cvss 6.1epss 0.01

    SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.

Page 1 of 2