CVE-2026-27472Server-Side Request Forgery in Spip

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 87.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19

Description

SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated attacker to make the server issue requests to arbitrary internal or external destinations. This vulnerability is not mitigated by the SPIP security screen.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

Affected Packages3 packages

NVDspip/spip4.4.04.4.9
debiandebian/spip< spip 4.4.9+dfsg-1 (forky)
Debianspip/spip< 4.4.11+dfsg-0+deb13u1+1

🔴Vulnerability Details

2
OSV
CVE-2026-27472: SPIP before 42026-02-19
GHSA
GHSA-jg7m-pjj3-mqmq: SPIP before 42026-02-19

📋Vendor Advisories

1
Debian
CVE-2026-27472: spip - SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-27472 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-27472 — Server-Side Request Forgery in Spip | cvebase