CVE-2026-22206
EUVD-2026-888426.02.2026, 21:28
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| spip | spip | 𝑥 < 4.4.10 |
𝑥
= Vulnerable software versions
Debian Releases