๐Ÿ” CVE Alert

CVE-2026-72710

CRITICAL 9.8

SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.

CWE CWE-915
Vendor spip
Product spip
Published Sep 11, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for spip spip

Be the first to know when new critical vulnerabilities affecting spip spip are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

SPIP / SPIP
0 < 4.4.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
blog.lexfo.fr: https://blog.lexfo.fr/casse-spip-sqli-to-rce.html blog.spip.net: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html vulncheck.com: https://www.vulncheck.com/advisories/spip-remote-code-execution-via-editer-objet-php-job-queue-injection

Credits

Franck Chevalier (Wayko)