CVE-2026-22206

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

02 Mar 2026, 15:58

Type Values Removed Values Added
First Time Spip spip
Spip
CPE cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
References () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html - () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html - Release Notes
References () https://git.spip.net/spip/spip - () https://git.spip.net/spip/spip - Product
References () https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags - () https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags - Third Party Advisory

27 Feb 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Las versiones de SPIP anteriores a la 4.4.10 contienen una vulnerabilidad de inyección SQL que permite a usuarios autenticados con bajos privilegios ejecutar consultas SQL arbitrarias manipulando técnicas de inyección basadas en UNION. Los atacantes pueden explotar esta falla de inyección SQL combinada con el procesamiento de etiquetas PHP para lograr la ejecución remota de código en el servidor.

26 Feb 2026, 21:28

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 21:28

Updated : 2026-03-02 15:58


NVD link : CVE-2026-22206

Mitre link : CVE-2026-22206

CVE.ORG link : CVE-2026-22206


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')