cbcvebase.

Debian Spip vulnerabilities

67 known vulnerabilities affecting debian/spip.

Total CVEs
67
CISA KEV
0
Public exploits
14
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH19MEDIUM36LOW4

Vulnerabilities

Page 1 of 4
CVE-2023-27372P1CRITICALCVSS 9.8ExploitedPoCfixed in spip 3.2.11-3+deb11u7 (bullseye)2023
CVE-2023-27372 [CRITICAL] CVE-2023-27372: spip - SPIP before 4.2.1 allows Remote Code Execution via form values in the public are... SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. Scope: local bullseye: resolved (fixed in 3.2.11-3+deb11u7) forky: resolved (fixed in 4.1.8+dfsg-1) sid: resolved (fixed in 4.1.8+dfsg-1) trixie: resolved (fixed in 4.1.8+dfsg-1)
debian
CVE-2024-7954P1LOWCVSS 9.8ExploitedPoCfixed in spip 4.3.0+dfsg-1 (forky)2024
CVE-2024-7954 [CRITICAL] CVE-2024-7954: spip - The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vu... The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. Scope: local bullseye: resolved forky: resolved (fixed in 4.3.0+dfsg-1) sid: resolved (fixed in 4.3.0+dfsg-1) trixie:
debian
CVE-2009-3041P2MEDIUMCVSS 7.5ExploitedPoCfixed in spip 2.0.9-1 (bullseye)2009
CVE-2009-3041 [HIGH] CVE-2009-3041: spip - SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access contro... SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009. Scope: local bullseye: resolved (fixed in 2.0.9-1) forky: resolved (fixed in 2.0.9-1) sid:
debian
CVE-2024-8517P1LOWCVSS 9.8PoCfixed in spip 4.3.2+dfsg-1 (forky)2024
CVE-2024-8517 [CRITICAL] CVE-2024-8517: spip - SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issu... SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request. Scope: local bullseye: resolved forky: resolved (fixed in 4.3.2+dfsg-1) sid: resolved (fixed in 4.3.2+dfsg-1) trixie: resolved (fixed in 4.3.2+d
debian
CVE-2016-7982P2HIGHCVSS 7.5PoCfixed in spip 3.1.3-1 (bullseye)2016
CVE-2016-7982 [HIGH] CVE-2016-7982: spip - Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 a... Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action. Scope: local bullseye: resolved (fixed in 3.1.3-1) forky: resolved (fixed in 3.1.3-1) sid: resolved (fixed in 3.1.3-1) trixie: resolved (fixed in 3.1.3-1)
debian
CVE-2016-7998P2HIGHCVSS 8.8PoCfixed in spip 3.1.3-1 (bullseye)2016
CVE-2016-7998 [HIGH] CVE-2016-7998: spip - The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote auth... The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action. Scope: local bullseye: resolved (fixed in 3.1.3-1) forky: resolved (fixed in 3.1.3-1) sid: resolved (fixed in 3.1.3-1) trixie:
debian
CVE-2013-4557P2HIGHCVSS 7.5PoCfixed in spip 2.1.24-1 (bullseye)2013
CVE-2013-4557 [HIGH] CVE-2013-4557: spip - The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, ... The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter. Scope: local bullseye: resolved (fixed in 2.1.24-1) forky: resolved (fixed in 2.1.24-1) sid: resolved (fixed in 2.1.24-1) trixie: resolved (fixed in 2.1.24-1)
debian
CVE-2013-2118P3HIGHCVSS 7.5PoCfixed in spip 2.1.22-1 (bullseye)2013
CVE-2013-2118 [HIGH] CVE-2013-2118: spip - SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows rem... SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php. Scope: local bullseye: resolved (fixed in 2.1.22-1) forky: resolved (fixed in 2.1.22-1) sid: resolved (fixed in 2.1.22-1) trixie: resolved (fixed in 2.1.22-1)
debian
CVE-2016-7980P3HIGHCVSS 8.8PoCfixed in spip 3.1.3-1 (bullseye)2016
CVE-2016-7980 [HIGH] CVE-2016-7980: spip - Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php i... Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code. Scope: local bullse
debian
CVE-2022-37155P2HIGHCVSS 8.8fixed in spip 3.2.11-3+deb11u5 (bullseye)2022
CVE-2022-37155 [HIGH] CVE-2022-37155: spip - RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute ar... RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. Scope: local bullseye: resolved (fixed in 3.2.11-3+deb11u5) forky: resolved (fixed in 4.1.5+dfsg-1) sid: resolved (fixed in 4.1.5+dfsg-1) trixie: resolved (fixed in 4.1.5+dfsg-1)
debian
CVE-2016-7981P3MEDIUMCVSS 6.1PoCfixed in spip 3.1.3-1 (bullseye)2016
CVE-2016-7981 [MEDIUM] CVE-2016-7981: spip - Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and ea... Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action. Scope: local bullseye: resolved (fixed in 3.1.3-1) forky: resolved (fixed in 3.1.3-1) sid: resolved (fixed in 3.1.3-1) trixie: resolved (fixed in 3.1.3-1)
debian
CVE-2026-22206P2HIGHCVSS 8.7fixed in spip 4.4.10+dfsg-1 (forky)2026
CVE-2026-22206 [HIGH] CVE-2026-22206: spip - SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows ... SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server. Scope: local bullseye: open forky: resolved (fi
debian
CVE-2006-1702P3HIGHCVSS 7.5PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-1702 [HIGH] CVE-2006-1702: spip - PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows ... PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. Scope: local bullseye: resolved (fixed in 2.0.6-1) forky: resolved (fixed in 2.0.6-1) sid: resolved (fixed in 2.0.6-1) trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2006-0625P3MEDIUMCVSS 6.4PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0625 [MEDIUM] CVE-2006-0625: spip - Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier all... Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3. Scope: local bullseye: resolved (fixed
debian
CVE-2006-0626P3MEDIUMCVSS 7.5PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0626 [HIGH] CVE-2006-0626: spip - SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier al... SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter. Scope: local bullseye: resolved (fixed in 2.0.6-1) forky: resolved (fixed in 2.0.6-1) sid: resolved (fixed in 2.0.6-1) trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2022-26846P3HIGHCVSS 8.8fixed in spip 3.2.11-3+deb11u3 (bullseye)2022
CVE-2022-26846 [HIGH] CVE-2022-26846: spip - SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to e... SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code. Scope: local bullseye: resolved (fixed in 3.2.11-3+deb11u3) forky: resolved (fixed in 4.0.5-1) sid: resolved (fixed in 4.0.5-1) trixie: resolved (fixed in 4.0.5-1)
debian
CVE-2017-9736P3CRITICALCVSS 9.8fixed in spip 3.1.4-3 (bullseye)2017
CVE-2017-9736 [CRITICAL] CVE-2017-9736: spip - SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharac... SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution. Scope: local bullseye: resolved (fixed in 3.1.4-3) forky: resolved (fixed in 3.1.4-3) sid: resolved (fixed in 3.1.4-3) trixie: resolved (fixed in 3.1.4-3)
debian
CVE-2021-44123P3HIGHCVSS 8.8fixed in spip 3.2.11-3+deb11u1 (bullseye)2021
CVE-2021-44123 [HIGH] CVE-2021-44123: spip - SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit t... SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it. Scope: local bullseye: resolved (fixed in 3.2.11-3+deb11u1) forky: resolved (fixed in 3.2.12-1) sid: resolved (fixed in 3.2.12-1) trixie: resolved (fixed in 3.
debian
CVE-2026-27475P3CRITICALCVSS 9.2fixed in spip 4.4.9+dfsg-1 (forky)2026
CVE-2026-27475 [CRITICAL] CVE-2026-27475: spip - SPIP before 4.4.9 allows Insecure Deserialization in the public area through the... SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can trigger arbitrary object instantiation and potentially achieve code execution. The use o
debian
CVE-2016-3154P3CRITICALCVSS 9.8fixed in spip 3.0.22-1 (bullseye)2016
CVE-2016-3154 [CRITICAL] CVE-2016-3154: spip - The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before ... The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object. Scope: local bullseye: resolved (fixed in 3.0.22-1) forky: resolved (fixed in 3.0.22-1) sid: resolved (fixed
debian
Debian Spip vulnerabilities | cvebase