Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spip HIGH 8.8
CVE-2026-33549

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data st…

Fix: 4.4.13+
Fix from $1,950 2026-03-22
Spip HIGH 8.8
CVE-2026-22206

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by…

Fix: 4.4.10+
Fix from $1,950 2026-02-26
Spip HIGH 7.5
CVE-2026-22205

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to acc…

Fix: 4.4.10+
Fix from $1,950 2026-02-26
Interface Traduction Objets HIGH 8.8
CVE-2026-27745

The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation i…

Fix: 2.2.2+
Fix from $1,950 2026-02-25
Interface Traduction Objets HIGH 8.8
CVE-2026-27747

The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability in interface_traduction_obje…

Fix: 2.2.2+
Fix from $1,950 2026-02-25
Jeux MEDIUM 6.1
CVE-2026-27746

The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin inco…

Fix: 4.1.1+
Fix from $1,600 2026-02-25
Referer Spam CRITICAL 9.8
CVE-2026-27743

The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_s…

Fix: 1.3.0+
Fix from $2,300 2026-02-25
Tickets CRITICAL 9.8
CVE-2026-27744

The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for publ…

Fix: 4.3.3+
Fix from $2,300 2026-02-25
Spip HIGH 8.1
CVE-2026-27475

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized d…

Fix: 4.4.9+
Fix from $1,950 2026-02-19
Spip MEDIUM 6.4
CVE-2026-27473

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized…

Fix: 4.4.9+
Fix from $1,600 2026-02-19
Spip MEDIUM 6.1
CVE-2026-27474

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() func…

Fix: 4.4.9+
Fix from $1,600 2026-02-19
Spip MEDIUM 5.4
CVE-2026-26345

SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The ec…

Fix: 4.4.8+
Fix from $1,600 2026-02-19
Spip MEDIUM 6.1
CVE-2026-26223

SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escap…

Fix: 4.4.8+
Fix from $1,600 2026-02-19
Saisies CRITICAL 9.8
CVE-2025-71243EPSS 5%

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. …

Fix: 5.11.1+
Fix from $2,300 2026-02-19
Spip MEDIUM 6.5
CVE-2025-71242

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorizati…

Fix: 4.1.20 / 4.2.17+
Fix from $1,600 2026-02-19
Spip MEDIUM 6.1
CVE-2025-71244

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visit…

Fix: 4.3.9 / 4.4.5+
Fix from $1,600 2026-02-19
Spip MEDIUM 6.1
CVE-2025-71241

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'trans…

Fix: 4.1.20 / 4.2.17+
Fix from $1,600 2026-02-19
Spip MEDIUM 5.4
CVE-2025-71240

SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript withi…

Fix: 4.2.15+
Fix from $1,600 2026-02-19
Spip MEDIUM 6.1
CVE-2023-53900

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can tric…

No fix yet
Fix from $1,600 2025-12-16
Spip MEDIUM 6.3
CVE-2024-53619

An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading …

No fix yet
Fix from $1,600 2024-11-26
Spip CRITICAL 9.8
CVE-2024-8517EPSS 95%

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary opera…

Fix: 4.1.18+
Fix from $2,300 2024-09-06
Spip MEDIUM 6.1
CVE-2024-23659

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.ut…

Fix: 4.1.14 / 4.2.8+
Fix from $1,600 2024-01-19
Spip MEDIUM 6.1
CVE-2023-52322

ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe character…

Fix: 4.1.13 / 4.2.7+
Fix from $1,600 2024-01-04
Spip CRITICAL 9.8
CVE-2023-24258

SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execu…

Fix: after 4.1.5
Fix from $2,300 2023-02-27
Spip HIGH 8.8
CVE-2022-37155EPSS 40%

RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

Fix: after 4.1.2
Fix from $1,950 2022-12-14
Spip HIGH 8.8
CVE-2022-28960

A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

Fix: 3.2.8+
Fix from $1,950 2022-05-19
Spip HIGH 8.8
CVE-2022-28961

Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where paramete…

Fix: after 3.1.13
Fix from $1,950 2022-05-19
Spip MEDIUM 6.1
CVE-2022-28959

Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute ar…

Fix: after 3.1.13
Fix from $1,600 2022-05-19
Spip HIGH 8.8
CVE-2021-44122

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/…

Patch available
Fix from $1,950 2022-01-26
Spip HIGH 8.8
CVE-2021-44123

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a d…

Patch available
Fix from $1,950 2022-01-26