Записи SPIP
76 опубликованных записей вендора spip.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 6,6 %
- Pre-auth RCE
- 19
- С записью об исправлении
- 96,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-94 Improper Control of Generation of Code ('Code Injection')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
76 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
69На этой неделе | CVE-2023-27372Готовый эксплойт | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled.spip · spip · CWE-502 | Критическая9,8 | — | 99,7 % | 28 февр. 2023 г. |
67На этой неделе | CVE-2024-8517Готовый эксплойт | SPIP Bigup Multipart File Upload OS Command Injectionspip · spip · CWE-73 | Критическая9,8 | — | 94,6 % | 6 сент. 2024 г. |
66На этой неделе | CVE-2024-7954Готовый эксплойт | SPIP porte_plume Plugin Arbitrary PHP Executionspip · spip · CWE-95 | Критическая9,8 | — | 90,1 % | 23 авг. 2024 г. |
47В плане | CVE-2022-37155Эксплойта нет | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.spip · spip · CWE-94 | Высокая8,8 | — | 40,0 % | 13 дек. 2022 г. |
40В плане | CVE-2017-9736Эксплойта нет | SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to causspip · spip · CWE-78 | Критическая9,8 | — | 3,2 % | 17 июн. 2017 г. |
40В плане | CVE-2020-28984Эксплойта нет | prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, displspip · spip | Критическая9,8 | — | 2,2 % | 23 нояб. 2020 г. |
40В плане | CVE-2016-3154Эксплойта нет | The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows rspip · spip · CWE-94 | Критическая9,8 | — | 1,8 % | 8 апр. 2016 г. |
40В плане | CVE-2016-3153Эксплойта нет | SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content,spip · spip · CWE-94 | Критическая9,8 | — | 1,8 % | 8 апр. 2016 г. |
40В плане | CVE-2008-5812Эксплойта нет | Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectospip · spip | Критическая10,0 | — | 1,5 % | 2 янв. 2009 г. |
40В плане | CVE-2012-4331Эксплойта нет | Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vecspip · spip | Критическая10,0 | — | 1,4 % | 14 авг. 2012 г. |
39Наблюдать | CVE-2016-7998Proof of concept | The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading aspip · spip · CWE-20 | Высокая8,8 | — | 13,6 % | 18 янв. 2017 г. |
39Наблюдать | CVE-2025-71243Готовый эксплойт | SPIP Saisies Plugin < 5.11.1 Remote Code Executionspip · saisies · CWE-94 | Критическая9,3 | — | 5,1 % | 19 февр. 2026 г. |
39Наблюдать | CVE-2023-24258Эксплойта нет | SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter.spip · spip · CWE-89 | Критическая9,8 | — | 1,6 % | 27 февр. 2023 г. |
38Наблюдать | CVE-2013-4557Готовый эксплойт | The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackersspip · spip · CWE-94 | Высокая7,5 | — | 25,3 % | 17 нояб. 2013 г. |
37Наблюдать | CVE-2026-27744Эксплойта нет | SPIP tickets < 4.3.3 Unauthenticated RCEspip · tickets · CWE-94 | Критическая9,3 | — | 1,4 % | 25 февр. 2026 г. |
37Наблюдать | CVE-2026-27743Эксплойта нет | SPIP referer_spam < 1.3.0 Unauthenticated SQL Injectionspip · referer spam · CWE-89 | Критическая9,3 | — | 0,7 % | 25 февр. 2026 г. |
36Наблюдать | CVE-2016-7982Proof of concept | Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files onspip · spip · CWE-22 | Высокая7,5 | — | 20,5 % | 18 янв. 2017 г. |
36Наблюдать | CVE-2016-7980Proof of concept | Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack tspip · spip · CWE-352 | Высокая8,8 | — | 4,1 % | 18 янв. 2017 г. |
36Наблюдать | CVE-2022-26846Эксплойта нет | SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.spip · spip | Высокая8,8 | — | 3,1 % | 10 мар. 2022 г. |
36Наблюдать | CVE-2019-11071Эксплойта нет | SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri ispip · spip · CWE-20 | Высокая8,8 | — | 2,5 % | 10 апр. 2019 г. |
36Наблюдать | CVE-2021-44123Эксплойта нет | SPIP 4.0.0 is affected by a remote command execution vulnerability.spip · spip · CWE-434 | Высокая8,8 | — | 2,4 % | 26 янв. 2022 г. |
36Наблюдать | CVE-2022-28960Эксплойта нет | A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.spip · spip · CWE-116 | Высокая8,8 | — | 2,0 % | 19 мая 2022 г. |
36Наблюдать | CVE-2022-28961Эксплойта нет | Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and wherespip · spip · CWE-89 | Высокая8,8 | — | 1,7 % | 19 мая 2022 г. |
36Наблюдать | CVE-2026-27475Proof of concept | SPIP < 4.4.9 Insecure Deserializationspip · spip · CWE-502 | Критическая9,2 | — | 0,9 % | 19 февр. 2026 г. |
35Наблюдать | CVE-2021-44122Эксплойта нет | SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrirspip · spip · CWE-352 | Высокая8,8 | — | 0,5 % | 26 янв. 2022 г. |
- CVE-2023-2737269На этой неделе
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled.
КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %spip · spip28 февр. 2023 г.
- CVE-2024-851767На этой неделе
SPIP Bigup Multipart File Upload OS Command Injection
КритическаяCVSS 9,8Готовый эксплойтEPSS 95 %spip · spip6 сент. 2024 г.
- CVE-2024-795466На этой неделе
SPIP porte_plume Plugin Arbitrary PHP Execution
КритическаяCVSS 9,8Готовый эксплойтEPSS 90 %spip · spip23 авг. 2024 г.
- CVE-2022-3715547В плане
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
ВысокаяCVSS 8,8Эксплойта нетEPSS 40 %spip · spip13 дек. 2022 г.
- CVE-2017-973640В плане
SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to caus
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %spip · spip17 июн. 2017 г.
- CVE-2020-2898440В плане
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, displ
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %spip · spip23 нояб. 2020 г.
- CVE-2016-315440В плане
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows r
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %spip · spip8 апр. 2016 г.
- CVE-2016-315340В плане
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content,
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %spip · spip8 апр. 2016 г.
- CVE-2008-581240В плане
Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vecto
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %spip · spip2 янв. 2009 г.
- CVE-2012-433140В плане
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vec
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %spip · spip14 авг. 2012 г.
- CVE-2016-799839Наблюдать
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a
ВысокаяCVSS 8,8Proof of conceptEPSS 14 %spip · spip18 янв. 2017 г.
- CVE-2025-7124339Наблюдать
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
КритическаяCVSS 9,3Готовый эксплойтEPSS 5 %spip · saisies19 февр. 2026 г.
- CVE-2023-2425839Наблюдать
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %spip · spip27 февр. 2023 г.
- CVE-2013-455738Наблюдать
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers
ВысокаяCVSS 7,5Готовый эксплойтEPSS 25 %spip · spip17 нояб. 2013 г.
- CVE-2026-2774437Наблюдать
SPIP tickets < 4.3.3 Unauthenticated RCE
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %spip · tickets25 февр. 2026 г.
- CVE-2026-2774337Наблюдать
SPIP referer_spam < 1.3.0 Unauthenticated SQL Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %spip · referer spam25 февр. 2026 г.
- CVE-2016-798236Наблюдать
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on
ВысокаяCVSS 7,5Proof of conceptEPSS 21 %spip · spip18 янв. 2017 г.
- CVE-2016-798036Наблюдать
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack t
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %spip · spip18 янв. 2017 г.
- CVE-2022-2684636Наблюдать
SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %spip · spip10 мар. 2022 г.
- CVE-2019-1107136Наблюдать
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri i
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %spip · spip10 апр. 2019 г.
- CVE-2021-4412336Наблюдать
SPIP 4.0.0 is affected by a remote command execution vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %spip · spip26 янв. 2022 г.
- CVE-2022-2896036Наблюдать
A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %spip · spip19 мая 2022 г.
- CVE-2022-2896136Наблюдать
Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %spip · spip19 мая 2022 г.
- CVE-2026-2747536Наблюдать
SPIP < 4.4.9 Insecure Deserialization
КритическаяCVSS 9,2Proof of conceptEPSS 1 %spip · spip19 февр. 2026 г.
- CVE-2021-4412235Наблюдать
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrir
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %spip · spip26 янв. 2022 г.