Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Spip

First CVE: Dec 22, 2005Active for: 21 yearsTotal CVEs: 79
56.9
VTI Score
TOP TARGET

Spip is a modestly distributed open-source content-management and web-publishing platform that maintains a disproportionately high profile in the vulnerability landscape despite its narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code, reflecting the platform's exposure as a web-facing application handling user input and database interactions. The exposure recurs across the core Spip product and associated modules—including translation interfaces, plugins, and customization layers—through weakness classes centered on input-handling and injection flaws: cross-site scripting, SQL injection, and code injection represent the durable structural risk points in a templating and database-driven architecture. Defenders deploying Spip should treat advisories as high-priority, inventory plugin dependencies carefully, and maintain rapid patching cycles for the core platform; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
79
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Spip over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 2005
20 years ago
Most Recent CVE
May 24, 2026
61 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (79 CVEs).

79 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-27372CRITICAL
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
Feb 28, 20239.892NOYES
CVE-2024-8517CRITICAL
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending
Sep 6, 20249.891NOYES
CVE-2024-7954CRITICAL
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can exe
Aug 23, 20249.889NOYES
CVE-2025-71243CRITICAL
The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vu
Feb 19, 20269.859NOYES
CVE-2022-37155HIGH
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
Dec 14, 20228.849NONO
CVE-2016-7998HIGH
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE o
Jan 18, 20178.845NOYES
CVE-2013-4557HIGH
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connec
Nov 18, 20137.541NOYES
CVE-2016-7980HIGH
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for
Jan 18, 20178.840NOYES
CVE-2016-7982HIGH
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in
Jan 18, 20177.538NOYES
CVE-2026-33549HIGH
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT misha
Mar 22, 20268.833NONO
View all 79 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products79 CVEs
47%
37%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network60 (75.9%)
Unknown19 (24.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (72.2%)
High3 (3.8%)
Unknown19 (24.1%)
User Interaction
None36 (45.6%)
Unknown19 (24.1%)
Required24 (30.4%)
Privileges Required
Low24 (30.4%)
High1 (1.3%)
None35 (44.3%)
Unknown19 (24.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (79 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
6.3% of CVEs· 98th percentile
Nuclei
5 CVEs
6.3% of CVEs· 96th percentile
ExploitDB
10 CVEs
12.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Spip.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Spip — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Spip's Products

View all 4 CNAs →

Top CWEs