CVE-2024-7954: Spip

Critical severity, CVSS 9.8. EPSS: 90.1% chance of exploitation in the next 30 days.

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

Affected products

  • Spip Spip: from 4.3.0-alpha, before 4.3.0-alpha2 (fixed in 4.3.0-alpha2); from 4.2.0, before 4.2.13 (fixed in 4.2.13); from 4.1.0, before 4.1.16 (fixed in 4.1.16)

Published 2024-08-23. Last modified 2026-06-17.