blog.spip.netVendor advisorypatch
https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html CVE-2026-22206
HIGH
SPIP < 4.4.10 SQL Injection RCE via Union & PHP Tags
Record summary
CVE-2026-22206 has a selected CVSS score of 8.7 (high).
Description
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 4.4.10 | affected |
References
4git.spip.netproduct
https://git.spip.net/spip/spip nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-22206 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags