CVE-2026-27472

MEDIUM

SPIP 4.4.0-4.4.8 - Authenticated Blind Server-Side Request Forgery via Syndicated Sites

Title source: llm
STIX 2.1

Description

SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated attacker to make the server issue requests to arbitrary internal or external destinations. This vulnerability is not mitigated by the SPIP security screen.

References (3)

Core 3

Scores

CVSS v3 4.3
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
spip/spip 4.4.0 - 4.4.9
Published Feb 19, 2026
Tracked Since Feb 19, 2026