Spip is a modestly distributed open-source content-management and web-publishing platform that maintains a disproportionately high profile in the vulnerability landscape despite its narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code, reflecting the platform's exposure as a web-facing application handling user input and database interactions. The exposure recurs across the core Spip product and associated modules—including translation interfaces, plugins, and customization layers—through weakness classes centered on input-handling and injection flaws: cross-site scripting, SQL injection, and code injection represent the durable structural risk points in a templating and database-driven architecture. Defenders deploying Spip should treat advisories as high-priority, inventory plugin dependencies carefully, and maintain rapid patching cycles for the core platform; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spip over time
Signals from CVEs in this vendor scope (79 CVEs).
79 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27372CRITICAL SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. | Feb 28, 2023 | 9.8 | 92 | NO | YES |
CVE-2024-8517CRITICAL SPIP before 4.3.2, 4.2.16, and
4.1.18 is vulnerable to a command injection issue. A
remote and unauthenticated attacker can execute arbitrary operating system commands by sending | Sep 6, 2024 | 9.8 | 91 | NO | YES |
CVE-2024-7954CRITICAL The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can exe | Aug 23, 2024 | 9.8 | 89 | NO | YES |
CVE-2025-71243CRITICAL The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vu | Feb 19, 2026 | 9.8 | 59 | NO | YES |
CVE-2022-37155HIGH RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. | Dec 14, 2022 | 8.8 | 49 | NO | NO |
CVE-2016-7998HIGH The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE o | Jan 18, 2017 | 8.8 | 45 | NO | YES |
CVE-2013-4557HIGH The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connec | Nov 18, 2013 | 7.5 | 41 | NO | YES |
CVE-2016-7980HIGH Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for | Jan 18, 2017 | 8.8 | 40 | NO | YES |
CVE-2016-7982HIGH Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in | Jan 18, 2017 | 7.5 | 38 | NO | YES |
CVE-2026-33549HIGH SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT misha | Mar 22, 2026 | 8.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (79 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spip.
Media articles that mention a CVE ID that affects a product developed by Spip — matched by CVE ID, not by vendor name.