VulnSea

SPIP has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 9.8 (critical), with 2 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.8
Publish → KEV
Last 90 days
3 prev 0

Products

  • SPIP 3
3
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

SPIP vulnerabilities

CVEs affecting SPIP, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-72710Critical· 9.8PoC
1w ago

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlle…

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlle…

AbyssalSPIP · SPIPEPSS 0.62%via NVD
CVE-2026-72708High· 7.5PoC
1w ago

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

MidnightSPIP · SPIPEPSS 0.32%via NVD
CVE-2026-72709Critical· 9.8PoC
1w ago

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

AbyssalSPIP · SPIPEPSS 0.36%via NVD
SPIP vulnerabilities (CVEs) · VulnSea