SPIP是SPIP开源的一个用于创建 Internet 站点的免费软件。 SPIP 5.11.0及之前版本存在代码注入漏洞,该漏洞源于存在远程代码执行漏洞,可能导致执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SPIP | Saisies pour formulaire | 5.4.0 ~ 5.11.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection) | https://github.com/Chocapikk/CVE-2025-71243 | POC Details |
| 2 | SPIP Saisies plugin 5.4.0 through 5.11.0 contains a remote code execution caused by an unspecified flaw, letting attackers execute arbitrary code on the server, exploit requires no special conditions. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-71243.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-27475 | 8.1 HIGH | SPIP < 4.4.9 Insecure Deserialization |
| CVE-2025-71242 | 6.5 MEDIUM | SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure |
| CVE-2026-27473 | 6.4 MEDIUM | SPIP < 4.4.9 Stored Cross-Site Scripting via Syndicated Sites |
| CVE-2026-26223 | 6.1 MEDIUM | SPIP < 4.4.8 Cross-Site Scripting via Iframe Tags in Private Area |
| CVE-2026-27474 | 6.1 MEDIUM | SPIP < 4.4.9 Cross-Site Scripting in Private Area (Incomplete Fix) |
| CVE-2025-71241 | 6.1 MEDIUM | SPIP < 4.3.6 Cross-Site Scripting in Private Area |
| CVE-2025-71244 | 6.1 MEDIUM | SPIP < 4.4.5 Open Redirect via Login Form |
| CVE-2026-26345 | 5.4 MEDIUM | SPIP < 4.4.8 Cross-Site Scripting in Public Area |
| CVE-2025-71240 | 5.4 MEDIUM | SPIP < 4.2.15 Cross-Site Scripting via Code Tags |
| CVE-2026-27472 | 4.3 MEDIUM | SPIP < 4.4.9 Blind Server-Side Request Forgery via Syndicated Sites |
No comments yet