CVE Feed

    Dashboard / CVE / CVE-2026-27743

    CVE-2026-27743

    The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE clauses without input validation or parameterization. The endpoints do not enforce authorization checks and do not use SPIP action protections such as securiser_action(), allowing remote attackers to execute arbitrary SQL queries.

    Published:Feb 25, 2026
    Last Modified:May 25, 2026
    EPS:Feb 25, 2026
    EPSS Score:0.00192
    CVSS Score:9.8

    Affected Products

    Vendor
    Spip
    Product
    Referer Spam
    Vendor
    Spip
    Product
    Spip

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High