📦 Spip

by Spip

🔍 What is Spip?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-8517

CRITICAL CVSS 9.8 Sep 6, 2024

CVE-2024-8517 is a critical remote code execution vulnerability in SPIP content management systems. Unauthenticated attackers can execute arbitrary operating system commands by uploading specially cra...

CVE-2020-28984

CRITICAL CVSS 9.8 Nov 23, 2020

CVE-2020-28984 is a critical vulnerability in SPIP CMS that allows unauthenticated attackers to execute arbitrary code on affected systems. The vulnerability exists in the preferences configuration fo...

CVE-2026-27475

HIGH CVSS 8.1 Feb 19, 2026

SPIP versions before 4.4.9 contain an insecure deserialization vulnerability in the public area through the table_valeur filter and DATA iterator. Attackers who can inject malicious serialized data (r...

CVE-2022-26846

HIGH CVSS 8.8 Mar 10, 2022

This vulnerability allows remote authenticated editors in SPIP content management systems to execute arbitrary code on the server. It affects SPIP installations where users have editor-level permissio...

CVE-2021-44122

HIGH CVSS 8.8 Jan 26, 2022

SPIP 4.0.0 has a CSRF vulnerability in multiple PHP files that allows authenticated attackers to execute malicious actions without user consent. Attackers can exploit this by tricking users into visit...

CVE-2026-27472

MEDIUM CVSS 4.3 Feb 19, 2026

This vulnerability allows authenticated attackers in SPIP's private area to perform blind Server-Side Request Forgery (SSRF) when editing syndicated sites. The application fails to validate syndicatio...

CVE-2026-27474

MEDIUM CVSS 6.1 Feb 19, 2026

This vulnerability allows cross-site scripting (XSS) attacks in SPIP's private area due to incomplete input sanitization. Attackers can inject malicious scripts through HTML tags that weren't properly...

CVE-2026-26345

MEDIUM CVSS 5.4 Feb 19, 2026

This CVE describes a cross-site scripting (XSS) vulnerability in SPIP CMS versions before 4.4.8. The echapper_html_suspect() function fails to properly sanitize certain edge-case inputs, allowing atta...

CVE-2025-71241

MEDIUM CVSS 6.1 Feb 19, 2026

This CVE describes a cross-site scripting (XSS) vulnerability in SPIP's private area where error messages from the 'transmettre' API are not properly sanitized. Attackers can inject malicious scripts ...

CVE-2024-53620

MEDIUM CVSS 4.8 Nov 26, 2024

This cross-site scripting (XSS) vulnerability in SPIP v4.3.3 allows authenticated users to inject malicious scripts into article titles, which execute when other users view affected articles. The vuln...