The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered environment rendering (#ENV**), which disables SPIP output filtering. As a result, an unauthenticated attacker can inject crafted content that is evaluated through SPIP's template processing chain, leading to execution of code in the context of the web server.
References
| Link | Resource |
|---|---|
| https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html | Release Notes |
| https://chocapikk.com/posts/2026/spip-plugins-vulnerabilities/ | Third Party Advisory |
| https://git.spip.net/spip-contrib-extensions/tickets/-/commit/869935b6687822ed79ad5477626a664d8ea6dcf7 | Patch |
| https://plugins.spip.net/tickets | Product |
| https://www.vulncheck.com/advisories/spip-tickets-unauthenticated-rce | Third Party Advisory |
Configurations
History
27 Feb 2026, 19:41
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Spip tickets
Spip |
|
| CPE | cpe:2.3:a:spip:tickets:*:*:*:*:*:*:*:* | |
| References | () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html - Release Notes | |
| References | () https://chocapikk.com/posts/2026/spip-plugins-vulnerabilities/ - Third Party Advisory | |
| References | () https://git.spip.net/spip-contrib-extensions/tickets/-/commit/869935b6687822ed79ad5477626a664d8ea6dcf7 - Patch | |
| References | () https://plugins.spip.net/tickets - Product | |
| References | () https://www.vulncheck.com/advisories/spip-tickets-unauthenticated-rce - Third Party Advisory |
26 Feb 2026, 21:28
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
25 Feb 2026, 16:23
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
25 Feb 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-25 04:16
Updated : 2026-02-27 19:41
NVD link : CVE-2026-27744
Mitre link : CVE-2026-27744
CVE.ORG link : CVE-2026-27744
JSON object : View
Products Affected
spip
- tickets
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
