Remote Code Execution Vulnerability in SPIP by SPIP Team
CVE-2026-77647
9.8CRITICAL
What is CVE-2026-77647?
A vulnerability in versions of SPIP prior to 4.4.20 allows unauthenticated remote attackers to execute arbitrary code. This flaw arises from improper recognition of PHP blocks, particularly with mismanaged strings that contain characters like '<'. Exploitation of this issue poses a significant risk to web applications using SPIP, as it can lead to unauthorized access and control over the affected systems, making timely updates crucial.
Affected Version(s)
SPIP 0 < 4.4.20
