SPIP kayıtları
spip üreticisine ait 76 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %6,6
- Pre-auth RCE
- 19
- Düzeltme kaydı olan
- %96,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-94 Improper Control of Generation of Code ('Code Injection')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
76 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
69Bu hafta | CVE-2023-27372Silahlaştırılmış | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled.spip · spip · CWE-502 | Kritik9,8 | — | %99,7 | 28 Şub 2023 |
67Bu hafta | CVE-2024-8517Silahlaştırılmış | SPIP Bigup Multipart File Upload OS Command Injectionspip · spip · CWE-73 | Kritik9,8 | — | %94,6 | 6 Eyl 2024 |
66Bu hafta | CVE-2024-7954Silahlaştırılmış | SPIP porte_plume Plugin Arbitrary PHP Executionspip · spip · CWE-95 | Kritik9,8 | — | %90,1 | 23 Ağu 2024 |
47Planlayın | CVE-2022-37155İstismar yok | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.spip · spip · CWE-94 | Yüksek8,8 | — | %40,0 | 13 Ara 2022 |
40Planlayın | CVE-2017-9736İstismar yok | SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to causspip · spip · CWE-78 | Kritik9,8 | — | %3,2 | 17 Haz 2017 |
40Planlayın | CVE-2020-28984İstismar yok | prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, displspip · spip | Kritik9,8 | — | %2,2 | 23 Kas 2020 |
40Planlayın | CVE-2016-3154İstismar yok | The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows rspip · spip · CWE-94 | Kritik9,8 | — | %1,8 | 8 Nis 2016 |
40Planlayın | CVE-2016-3153İstismar yok | SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content,spip · spip · CWE-94 | Kritik9,8 | — | %1,8 | 8 Nis 2016 |
40Planlayın | CVE-2008-5812İstismar yok | Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectospip · spip | Kritik10,0 | — | %1,5 | 2 Oca 2009 |
40Planlayın | CVE-2012-4331İstismar yok | Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vecspip · spip | Kritik10,0 | — | %1,4 | 14 Ağu 2012 |
39İzleyin | CVE-2016-7998Kavram kanıtı | The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading aspip · spip · CWE-20 | Yüksek8,8 | — | %13,6 | 18 Oca 2017 |
39İzleyin | CVE-2025-71243Silahlaştırılmış | SPIP Saisies Plugin < 5.11.1 Remote Code Executionspip · saisies · CWE-94 | Kritik9,3 | — | %5,1 | 19 Şub 2026 |
39İzleyin | CVE-2023-24258İstismar yok | SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter.spip · spip · CWE-89 | Kritik9,8 | — | %1,6 | 27 Şub 2023 |
38İzleyin | CVE-2013-4557Silahlaştırılmış | The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackersspip · spip · CWE-94 | Yüksek7,5 | — | %25,3 | 17 Kas 2013 |
37İzleyin | CVE-2026-27744İstismar yok | SPIP tickets < 4.3.3 Unauthenticated RCEspip · tickets · CWE-94 | Kritik9,3 | — | %1,4 | 25 Şub 2026 |
37İzleyin | CVE-2026-27743İstismar yok | SPIP referer_spam < 1.3.0 Unauthenticated SQL Injectionspip · referer spam · CWE-89 | Kritik9,3 | — | %0,7 | 25 Şub 2026 |
36İzleyin | CVE-2016-7982Kavram kanıtı | Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files onspip · spip · CWE-22 | Yüksek7,5 | — | %20,5 | 18 Oca 2017 |
36İzleyin | CVE-2016-7980Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack tspip · spip · CWE-352 | Yüksek8,8 | — | %4,1 | 18 Oca 2017 |
36İzleyin | CVE-2022-26846İstismar yok | SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.spip · spip | Yüksek8,8 | — | %3,1 | 10 Mar 2022 |
36İzleyin | CVE-2019-11071İstismar yok | SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri ispip · spip · CWE-20 | Yüksek8,8 | — | %2,5 | 10 Nis 2019 |
36İzleyin | CVE-2021-44123İstismar yok | SPIP 4.0.0 is affected by a remote command execution vulnerability.spip · spip · CWE-434 | Yüksek8,8 | — | %2,4 | 26 Oca 2022 |
36İzleyin | CVE-2022-28960İstismar yok | A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.spip · spip · CWE-116 | Yüksek8,8 | — | %2,0 | 19 May 2022 |
36İzleyin | CVE-2022-28961İstismar yok | Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and wherespip · spip · CWE-89 | Yüksek8,8 | — | %1,7 | 19 May 2022 |
36İzleyin | CVE-2026-27475Kavram kanıtı | SPIP < 4.4.9 Insecure Deserializationspip · spip · CWE-502 | Kritik9,2 | — | %0,9 | 19 Şub 2026 |
35İzleyin | CVE-2021-44122İstismar yok | SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrirspip · spip · CWE-352 | Yüksek8,8 | — | %0,5 | 26 Oca 2022 |
- CVE-2023-2737269Bu hafta
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled.
KritikCVSS 9,8SilahlaştırılmışEPSS %100spip · spip28 Şub 2023
- CVE-2024-851767Bu hafta
SPIP Bigup Multipart File Upload OS Command Injection
KritikCVSS 9,8SilahlaştırılmışEPSS %95spip · spip6 Eyl 2024
- CVE-2024-795466Bu hafta
SPIP porte_plume Plugin Arbitrary PHP Execution
KritikCVSS 9,8SilahlaştırılmışEPSS %90spip · spip23 Ağu 2024
- CVE-2022-3715547Planlayın
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
YüksekCVSS 8,8İstismar yokEPSS %40spip · spip13 Ara 2022
- CVE-2017-973640Planlayın
SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to caus
KritikCVSS 9,8İstismar yokEPSS %3spip · spip17 Haz 2017
- CVE-2020-2898440Planlayın
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, displ
KritikCVSS 9,8İstismar yokEPSS %2spip · spip23 Kas 2020
- CVE-2016-315440Planlayın
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows r
KritikCVSS 9,8İstismar yokEPSS %2spip · spip8 Nis 2016
- CVE-2016-315340Planlayın
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content,
KritikCVSS 9,8İstismar yokEPSS %2spip · spip8 Nis 2016
- CVE-2008-581240Planlayın
Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vecto
KritikCVSS 10,0İstismar yokEPSS %2spip · spip2 Oca 2009
- CVE-2012-433140Planlayın
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vec
KritikCVSS 10,0İstismar yokEPSS %1spip · spip14 Ağu 2012
- CVE-2016-799839İzleyin
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a
YüksekCVSS 8,8Kavram kanıtıEPSS %14spip · spip18 Oca 2017
- CVE-2025-7124339İzleyin
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
KritikCVSS 9,3SilahlaştırılmışEPSS %5spip · saisies19 Şub 2026
- CVE-2023-2425839İzleyin
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter.
KritikCVSS 9,8İstismar yokEPSS %2spip · spip27 Şub 2023
- CVE-2013-455738İzleyin
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers
YüksekCVSS 7,5SilahlaştırılmışEPSS %25spip · spip17 Kas 2013
- CVE-2026-2774437İzleyin
SPIP tickets < 4.3.3 Unauthenticated RCE
KritikCVSS 9,3İstismar yokEPSS %1spip · tickets25 Şub 2026
- CVE-2026-2774337İzleyin
SPIP referer_spam < 1.3.0 Unauthenticated SQL Injection
KritikCVSS 9,3İstismar yokEPSS %1spip · referer spam25 Şub 2026
- CVE-2016-798236İzleyin
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on
YüksekCVSS 7,5Kavram kanıtıEPSS %21spip · spip18 Oca 2017
- CVE-2016-798036İzleyin
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack t
YüksekCVSS 8,8Kavram kanıtıEPSS %4spip · spip18 Oca 2017
- CVE-2022-2684636İzleyin
SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.
YüksekCVSS 8,8İstismar yokEPSS %3spip · spip10 Mar 2022
- CVE-2019-1107136İzleyin
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri i
YüksekCVSS 8,8İstismar yokEPSS %3spip · spip10 Nis 2019
- CVE-2021-4412336İzleyin
SPIP 4.0.0 is affected by a remote command execution vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %2spip · spip26 Oca 2022
- CVE-2022-2896036İzleyin
A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.
YüksekCVSS 8,8İstismar yokEPSS %2spip · spip19 May 2022
- CVE-2022-2896136İzleyin
Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where
YüksekCVSS 8,8İstismar yokEPSS %2spip · spip19 May 2022
- CVE-2026-2747536İzleyin
SPIP < 4.4.9 Insecure Deserialization
KritikCVSS 9,2Kavram kanıtıEPSS %1spip · spip19 Şub 2026
- CVE-2021-4412235İzleyin
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrir
YüksekCVSS 8,8İstismar yokEPSS %0spip · spip26 Oca 2022