A critical unauthenticated remote code execution (RCE) flaw, tracked as CVE-2025-71243, was disclosed in the SPIP Saisies pour formulaire (Saisies) plugin affecting versions 5.4.0 through 5.11.0. The issue is categorized as CWE-94 (code injection) and allows an attacker to execute arbitrary code on the server; remediation is to upgrade to Saisies 5.11.1 or later. Technical analysis indicates exploitation is possible via PHP code injection through the _anciennes_valeurs form parameter, where attacker-controlled input is interpolated into a PHP template rendered with interdire_scripts=false, enabling <?php ... ?> execution server-side.
Separately, SPIP core also received a high-severity security fix for CVE-2025-71250, an insecure deserialization issue (CWE-502) in SPIP versions before 4.4.9 involving the table_valeur filter and the DATA iterator accepting serialized data. This deserialization weakness requires a precondition (the attacker must be able to place malicious serialized content via prior access or another vulnerability) and is noted as not mitigated by the SPIP security screen; the use of serialized data in these components is deprecated and planned for removal in SPIP 5. While both items affect the SPIP ecosystem, they are distinct vulnerabilities with different affected components, prerequisites, and fixes.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A ProjectDiscovery Nuclei templates pull request added a template for CVE-2025-71243, describing the issue as an unauthenticated RCE in the SPIP Saisies plugin via PHP template injection. This made scanner-based detection content available for the flaw.
A Metasploit Framework pull request for a module targeting CVE-2025-71243 was updated via a force-push, rewriting the branch history from commit e3eb842 to 429c5ff. This indicates active weaponization and exploit module development for the vulnerability.
The CVE record for CVE-2025-71243 was received by disclosure@vulncheck.com, classifying the issue as CWE-94 and documenting network-exploitable unauthenticated RCE in the SPIP Saisies plugin. The entry included CVSS v3.1 and v4.0 scoring and references to the vendor notice and advisory.
A public write-up described CVE-2025-71243 as a PHP code injection issue via the `_anciennes_valeurs` parameter that can lead to server-side code execution during form rendering without authentication. The analysis also discussed exposure conditions, exploitation parallels to CVE-2023-27372, and mitigation guidance.
A critical unauthenticated remote code execution flaw affecting SPIP Saisies plugin versions 5.4.0 through 5.11.0 was addressed in version 5.11.1. SPIP's security notice advised users to update to the fixed release or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcecvefeed.io
Open sourcechocapikk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.