Known Vulnerabilities for SPIP by SPIP
Listed below are 10 of the newest known vulnerabilities associated with "SPIP" by "SPIP".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-48832 json | action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability. | Not Provided | 2026-05-24 | 2026-05-26 |
| CVE-2026-33549 json | SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the edit... | Not Provided | 2026-03-22 | 2026-04-02 |
| CVE-2026-8430 json | SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain ng... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-8429 json | SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to exe... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2024-23659 json | 6.1 - MEDIUM | 2024-01-19 | 2024-01-25 | |
| CVE-2023-53900 json | Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external l... | 6.1 - MEDIUM | 2025-12-16 | 2026-04-07 |
| CVE-2023-52322 json | 6.1 - MEDIUM | 2024-01-04 | 2024-03-15 | |
| CVE-2023-27372 json | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fi... | 9.8 - CRITICAL | 2023-02-28 | 2023-06-21 |
| CVE-2023-24258 json | SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability a... | 9.8 - CRITICAL | 2023-02-27 | 2023-03-24 |
| CVE-2022-37155 json | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. | 8.8 - HIGH | 2022-12-14 | 2023-01-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Spip | Spip | 3.2.8 | |||
| Application | Spip | Spip | 3.2.7 | |||
| Application | Spip | Spip | 3.2.5 | |||
| Application | Spip | Spip | 3.2.4 | |||
| Application | Spip | Spip | 3.2.3 | |||
| Application | Spip | Spip | 3.2.2 | |||
| Application | Spip | Spip | 3.2.1 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2.0 | |||
| Application | Spip | Spip | 3.2 | |||
| Application | Spip | Spip | 3.1.9 | |||
| Application | Spip | Spip | 3.1.6 | |||
| Application | Spip | Spip | 3.1.5 | |||
| Application | Spip | Spip | 3.1.4 | |||
| Application | Spip | Spip | 3.1.3 | |||
| Application | Spip | Spip | 3.1.2 | |||
| Application | Spip | Spip | 3.1.11 |