CVE-2023-27372: Debian Linux

Critical severity, CVSS 9.8. EPSS: 99.7% chance of exploitation in the next 30 days.

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Spip Spip: before 3.2.18 (fixed in 3.2.18); from 4.0.0, before 4.0.10 (fixed in 4.0.10); from 4.1.0, before 4.1.8 (fixed in 4.1.8); version 4.2.0 only

Published 2023-02-28. Last modified 2026-06-17.