CVE-2026-22206: Spip

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.

Affected products

  • Spip Spip: before 4.4.10 (fixed in 4.4.10)

Published 2026-02-26. Last modified 2026-06-17.