cbcvebase.

Debian Spip vulnerabilities

67 known vulnerabilities affecting debian/spip.

Total CVEs
67
CISA KEV
0
Public exploits
14
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH19MEDIUM36LOW4

Vulnerabilities

Page 2 of 4
CVE-2022-28960P3HIGHCVSS 8.8fixed in spip 3.2.8-1 (bullseye)2022
CVE-2022-28960 [HIGH] CVE-2022-28960: spip - A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute ... A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire. Scope: local bullseye: resolved (fixed in 3.2.8-1) forky: resolved (fixed in 3.2.8-1) sid: resolved (fixed in 3.2.8-1) trixie: resolved (fixed in 3.2.8-1)
debian
CVE-2016-3153P3CRITICALCVSS 9.8fixed in spip 3.0.22-1 (bullseye)2016
CVE-2016-3153 [CRITICAL] CVE-2016-3153: spip - SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remot... SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function. Scope: local bullseye: resolved (fixed in 3.0.22-1) forky: resolved (fixed in 3.0.22-1) sid: resolved (fixed in 3.0.22-1) trixie: resolved (fixed in 3.0.22-1)
debian
CVE-2026-22205P3HIGHCVSS 8.7fixed in spip 4.4.10+dfsg-1 (forky)2026
CVE-2026-22205 [HIGH] CVE-2026-22205: spip - SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability cau... SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data. Scope: local bullseye: open forky: resolved (fixed in 4.4.1
debian
CVE-2023-24258P3CRITICALCVSS 9.8fixed in spip 3.2.11-3+deb11u6 (bullseye)2023
CVE-2023-24258 [CRITICAL] CVE-2023-24258: spip - SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability ... SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request. Scope: local bullseye: resolved (fixed in 3.2.11-3+deb11u6) forky: resolved (fixed in 4.1.7+dfsg-1) sid: resolved (fixed in 4.1.7+dfsg-1) trixie: resolved (fixed in 4.1.7+d
debian
CVE-2019-11071P3HIGHCVSS 8.8fixed in spip 3.2.4-1 (bullseye)2019
CVE-2019-11071 [HIGH] CVE-2019-11071: spip - SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to exe... SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled. Scope: local bullseye: resolved (fixed in 3.2.4-1) forky: resolved (fixed in 3.2.4-1) sid: resolved (fixed in 3.2.4-1) trixie: resolved (fixed in 3.2.4-1)
debian
CVE-2026-33549P3MEDIUMCVSS 6.7fixed in spip 4.4.13+dfsg-1 (forky)2026
CVE-2026-33549 [MEDIUM] CVE-2026-33549: spip - SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment ... SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling. Scope: local bullseye: open forky: resolved (fixed in 4.4.13+dfsg-1) sid: resolved (fixed in 4.4.13+dfsg-1) trixie: resolved (fixed in 4.4.13+dfsg-0+deb13u1)
debian
CVE-2022-28961P3HIGHCVSS 8.8fixed in spip 3.2.8-1 (bullseye)2022
CVE-2022-28961 [HIGH] CVE-2022-28961: spip - Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL inje... Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters. Scope: local bullseye: resolved (fixed in 3.2.8-1) forky: resolved (fixed in 3.2.8-1) sid: resolved (fixed in 3.2.8-1) trixie: resolved (fixed in 3.2.8-1)
debian
CVE-2020-28984P3CRITICALCVSS 9.8fixed in spip 3.2.8-1 (bullseye)2020
CVE-2020-28984 [CRITICAL] CVE-2020-28984: spip - prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not prope... prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters. Scope: local bullseye: resolved (fixed in 3.2.8-1) forky: resolved (fixed in 3.2.8-1) sid: resolved (fixed in 3.2.8-1) trixie: resolved (fixed in 3.2.8-1)
debian
CVE-2006-0518P4MEDIUMCVSS 4.3PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0518 [MEDIUM] CVE-2006-0518: spip - Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earli... Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter. Scope: local bullseye: resolved (fixed in 2.0.6-1) forky: resolved (fixed in 2.0.6-1) sid: resolved (fixed in 2.0.6-1) trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2016-7999P3HIGHCVSS 7.4fixed in spip 3.1.3-1 (bullseye)2016
CVE-2016-7999 [HIGH] CVE-2016-7999: spip - ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to... ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action. Scope: local bullseye: resolved (fixed in 3.1.3-1) forky: resolved (fixed in 3.1.3-1) sid: resolved (fixed in 3.1.3-1) trixie: resolved (fixed in 3.1.3-1)
debian
CVE-2025-71242P3MEDIUMCVSS 5.3fixed in spip 4.3.6+dfsg-1 (forky)2025
CVE-2025-71242 [MEDIUM] CVE-2025-71242: spip - SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in ... SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted content. This vulnerability is not mitigated by the SPIP security screen.
debian
CVE-2021-44122P3HIGHCVSS 8.8fixed in spip 3.2.11-3+deb11u1 (bullseye)2021
CVE-2021-44122 [HIGH] CVE-2021-44122: spip - SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in e... SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability
debian
CVE-2006-0517P3MEDIUMCVSS 7.5fixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0517 [HIGH] CVE-2006-0517: spip - Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 ... Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to "session handling"; and (5) when posting "petitions". Scop
debian
CVE-2008-5813P3HIGHCVSS 7.5fixed in spip 2.0.6-1 (bullseye)2008
CVE-2008-5813 [HIGH] CVE-2008-5813: spip - SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 ... SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third party information. Scope: local bullseye: resolved (fixed in 2.0.6-1) forky: resolved (fixed in 2.0.6-1) sid: resolved (fixed
debian
CVE-2019-16391P3MEDIUMCVSS 6.5fixed in spip 3.2.5-1 (bullseye)2019
CVE-2019-16391 [MEDIUM] CVE-2019-16391: spip - SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify ... SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php. Scope: local bullseye: resolved (fixed in 3.2.5-1) forky: resolved (fixed in 3.2.5-1) sid: resolved (fixed in 3.2.5-1) trixie: resolved (fixed
debian
CVE-2019-19830P4MEDIUMCVSS 6.5fixed in spip 3.2.7-1 (bullseye)2019
CVE-2019-19830 [MEDIUM] CVE-2019-19830: spip - _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated aut... _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database. Scope: local bullseye: resolved (fixed in 3.2.7-1) forky: resolved (fixed in 3.2.7-1) sid: resolved (fixed in 3.2.7-1) trixie: resolved (fixed in 3.2.7-1)
debian
CVE-2019-16394P3MEDIUMCVSS 5.3fixed in spip 3.2.5-1 (bullseye)2019
CVE-2019-16394 [MEDIUM] CVE-2019-16394: spip - SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from t... SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers. Scope: local bullseye: resolved (fixed in 3.2.5-1) forky: resolved (fixed in 3.2.5-1) sid: resolved (fixed in 3.2.5-1) trixie: resolved (fixed in 3.2.5-1)
debian
CVE-2026-27473P4MEDIUMCVSS 5.1fixed in spip 4.4.9+dfsg-1 (forky)2026
CVE-2026-27473 [MEDIUM] CVE-2026-27473: spip - SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites ... SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts that execute when other administrators view the syndicated site details. Scope: local bullse
debian
CVE-2007-4525P4HIGHCVSS 7.5fixed in spip 2.0.6-1 (bullseye)2007
CVE-2007-4525 [HIGH] CVE-2007-4525: spip - PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows ... PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the sco
debian
CVE-2008-5812P4CRITICALCVSS 10.0fixed in spip 2.0.6-1 (bullseye)2008
CVE-2008-5812 [CRITICAL] CVE-2008-5812: spip - Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2... Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectors. Scope: local bullseye: resolved (fixed in 2.0.6-1) forky: resolved (fixed in 2.0.6-1) sid: resolved (fixed in 2.0.6-1) trixie: resolved (fixed in 2.0.6-1)
debian