Spip

Spip

78 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 12.05.2026 18:43:25
  • Zuletzt bearbeitet 13.05.2026 15:26:44

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this...

  • EPSS 0.2%
  • Veröffentlicht 12.05.2026 18:32:17
  • Zuletzt bearbeitet 13.05.2026 15:26:44

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability to achieve code execution that...

  • EPSS 0.04%
  • Veröffentlicht 22.03.2026 02:03:47
  • Zuletzt bearbeitet 17.04.2026 21:13:29

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

  • EPSS 0.43%
  • Veröffentlicht 26.02.2026 20:18:14
  • Zuletzt bearbeitet 02.03.2026 16:08:10

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to by...

  • EPSS 0.22%
  • Veröffentlicht 26.02.2026 20:17:58
  • Zuletzt bearbeitet 02.03.2026 15:58:07

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combine...

  • EPSS 0.19%
  • Veröffentlicht 19.02.2026 18:39:24
  • Zuletzt bearbeitet 24.02.2026 19:37:54

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access o...

  • EPSS 0.07%
  • Veröffentlicht 19.02.2026 18:38:57
  • Zuletzt bearbeitet 02.03.2026 15:16:36

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an att...

  • EPSS 0.07%
  • Veröffentlicht 19.02.2026 18:38:26
  • Zuletzt bearbeitet 24.02.2026 19:44:24

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to...

  • EPSS 0.06%
  • Veröffentlicht 19.02.2026 18:38:02
  • Zuletzt bearbeitet 24.02.2026 19:45:15

SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated atta...

  • EPSS 0.07%
  • Veröffentlicht 19.02.2026 15:26:05
  • Zuletzt bearbeitet 02.03.2026 15:16:35

SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. Th...