SPIP

3 known vulnerabilities in SPIP, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-72710 CVSS 9.3 critical SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write…
  • CVE-2026-72709 CVSS 9.3 critical SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows…
  • CVE-2026-72708 CVSS 8.7 high SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated…