Перейти к содержимому
Noroxi

Записи SPIP

76 опубликованных записей вендора spip.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
5 · 6,6 %
Pre-auth RCE
19
С записью об исправлении
96,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

76 записей
  • CVE-2023-27372
    69На этой неделе

    SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %

    spip · spip28 февр. 2023 г.

  • CVE-2024-8517
    67На этой неделе

    SPIP Bigup Multipart File Upload OS Command Injection

    КритическаяCVSS 9,8Готовый эксплойтEPSS 95 %

    spip · spip6 сент. 2024 г.

  • CVE-2024-7954
    66На этой неделе

    SPIP porte_plume Plugin Arbitrary PHP Execution

    КритическаяCVSS 9,8Готовый эксплойтEPSS 90 %

    spip · spip23 авг. 2024 г.

  • CVE-2022-37155
    47В плане

    RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 40 %

    spip · spip13 дек. 2022 г.

  • CVE-2017-9736
    40В плане

    SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to caus

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    spip · spip17 июн. 2017 г.

  • CVE-2020-28984
    40В плане

    prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, displ

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    spip · spip23 нояб. 2020 г.

  • CVE-2016-3154
    40В плане

    The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows r

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    spip · spip8 апр. 2016 г.

  • CVE-2016-3153
    40В плане

    SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content,

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    spip · spip8 апр. 2016 г.

  • CVE-2008-5812
    40В плане

    Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vecto

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    spip · spip2 янв. 2009 г.

  • CVE-2012-4331
    40В плане

    Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vec

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    spip · spip14 авг. 2012 г.

  • CVE-2016-7998
    39Наблюдать

    The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a

    ВысокаяCVSS 8,8Proof of conceptEPSS 14 %

    spip · spip18 янв. 2017 г.

  • CVE-2025-71243
    39Наблюдать

    SPIP Saisies Plugin < 5.11.1 Remote Code Execution

    КритическаяCVSS 9,3Готовый эксплойтEPSS 5 %

    spip · saisies19 февр. 2026 г.

  • CVE-2023-24258
    39Наблюдать

    SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    spip · spip27 февр. 2023 г.

  • CVE-2013-4557
    38Наблюдать

    The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 25 %

    spip · spip17 нояб. 2013 г.

  • CVE-2026-27744
    37Наблюдать

    SPIP tickets < 4.3.3 Unauthenticated RCE

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    spip · tickets25 февр. 2026 г.

  • CVE-2026-27743
    37Наблюдать

    SPIP referer_spam < 1.3.0 Unauthenticated SQL Injection

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    spip · referer spam25 февр. 2026 г.

  • CVE-2016-7982
    36Наблюдать

    Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on

    ВысокаяCVSS 7,5Proof of conceptEPSS 21 %

    spip · spip18 янв. 2017 г.

  • CVE-2016-7980
    36Наблюдать

    Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack t

    ВысокаяCVSS 8,8Proof of conceptEPSS 4 %

    spip · spip18 янв. 2017 г.

  • CVE-2022-26846
    36Наблюдать

    SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    spip · spip10 мар. 2022 г.

  • CVE-2019-11071
    36Наблюдать

    SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    spip · spip10 апр. 2019 г.

  • CVE-2021-44123
    36Наблюдать

    SPIP 4.0.0 is affected by a remote command execution vulnerability.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    spip · spip26 янв. 2022 г.

  • CVE-2022-28960
    36Наблюдать

    A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    spip · spip19 мая 2022 г.

  • CVE-2022-28961
    36Наблюдать

    Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    spip · spip19 мая 2022 г.

  • CVE-2026-27475
    36Наблюдать

    SPIP < 4.4.9 Insecure Deserialization

    КритическаяCVSS 9,2Proof of conceptEPSS 1 %

    spip · spip19 февр. 2026 г.

  • CVE-2021-44122
    35Наблюдать

    SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrir

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    spip · spip26 янв. 2022 г.