CVE-2013-2118: Spip

High severity, CVSS 7.5. EPSS: 9% chance of exploitation in the next 30 days.

SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.

Affected products

  • Spip Spip: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.0.5 only; …

Published 2013-07-09. Last modified 2026-06-16.