Known Vulnerabilities for SPIP by SPIP
Listed below are 10 of the newest known vulnerabilities associated with "SPIP" by "SPIP".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33549 json | SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the edit... | Not Provided | 2026-03-22 | 2026-04-02 |
| CVE-2024-23659 json | 6.1 - MEDIUM | 2024-01-19 | 2024-01-25 | |
| CVE-2023-52322 json | 6.1 - MEDIUM | 2024-01-04 | 2024-03-15 | |
| CVE-2023-27372 json | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fi... | 9.8 - CRITICAL | 2023-02-28 | 2023-06-21 |
| CVE-2023-24258 json | SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability a... | 9.8 - CRITICAL | 2023-02-27 | 2023-03-24 |
| CVE-2022-37155 json | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. | 8.8 - HIGH | 2022-12-14 | 2023-01-30 |
| CVE-2022-28961 json | Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier... | 8.8 - HIGH | 2022-05-19 | 2022-05-26 |
| CVE-2022-28960 json | A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at... | 8.8 - HIGH | 2022-05-19 | 2023-08-08 |
| CVE-2022-28959 json | Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows... | 6.1 - MEDIUM | 2022-05-19 | 2022-05-26 |
| CVE-2022-26847 json | SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects. | 5.3 - MEDIUM | 2022-03-10 | 2022-03-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Spip | Spip | 3.2.8 | |||
| Application | Spip | Spip | 3.2.7 | |||
| Application | Spip | Spip | 3.2.5 | |||
| Application | Spip | Spip | 3.2.4 | |||
| Application | Spip | Spip | 3.2.3 | |||
| Application | Spip | Spip | 3.2.2 | |||
| Application | Spip | Spip | 3.2.1 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2 | |||
| Application | Spip | Spip | 3.1.9 | |||
| Application | Spip | Spip | 3.1.6 | |||
| Application | Spip | Spip | 3.1.5 | |||
| Application | Spip | Spip | 3.1.4 | |||
| Application | Spip | Spip | 3.1.3 | |||
| Application | Spip | Spip | 3.1.2 | |||
| Application | Spip | Spip | 3.1.11 |