SPIP Vulnerabilities and Affected Products
Vulnerabilities associated with tickets.
Products
Clear product- SPIP24 vulnerabilities
- interface_traduction_objets2 vulnerabilities
- jeux1 vulnerability
- porte_plume plugin1 vulnerability
- referer_spam1 vulnerability
- saisies1 vulnerability
- Saisies pour formulaire1 vulnerability
- tickets1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-27744CRITICAL | SPIP tickets < 4.3.3 Unauthenticated RCEThe SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered environment rendering (#ENV**), which disables SPIP output filtering. As a result, an unauthenticated attacker can inject crafted content that is evaluated through SPIP's template processing chain, leading to execution of … CWE-94Feb 25, 2026 | CVSS9.3v4.0 | EPSS0.908% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |