Products: 8
    Vulnerabilities: 89
    Known Exploited: 0
    17
    Critical Level Threats
    29
    High Level Threats
    37
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-72710

    SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection

    Last Modified: Sep 11, 2026
    Published: Sep 11, 2026

    CVE-2026-72709

    SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur

    Last Modified: Sep 11, 2026
    Published: Sep 11, 2026

    CVE-2026-72708

    SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter

    Last Modified: Sep 11, 2026
    Published: Sep 11, 2026

    CVE-2026-77806

    Unauthenticated Remote Code Execution via Malformed X‑Spip‑Filtre Header in SPIP

    Last Modified: Aug 27, 2026
    Published: Aug 21, 2026

    CVE-2026-77647

    SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.

    Last Modified: Aug 25, 2026
    Published: Aug 20, 2026
    Items Per Page
    Spip Vulnerabilities & Security CVEs | CVE-DB