CVE-2025-71243: Spip Saisies
Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.
The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later.
Affected products
- Spip Saisies: from 5.4.0, before 5.11.1 (fixed in 5.11.1)
Published 2026-02-19. Last modified 2026-06-17.