Remote Code Execution Vulnerability in SPIP by SPIP Team
CVE-2026-77647

9.8CRITICAL

Key Information:

Vendor

Spip

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77647?

A vulnerability in versions of SPIP prior to 4.4.20 allows unauthenticated remote attackers to execute arbitrary code. This flaw arises from improper recognition of PHP blocks, particularly with mismanaged strings that contain characters like '<'. Exploitation of this issue poses a significant risk to web applications using SPIP, as it can lead to unauthorized access and control over the affected systems, making timely updates crucial.

Affected Version(s)

SPIP 0 < 4.4.20

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.