SPIP released version 4.4.18 as a critical security update to remediate multiple vulnerabilities affecting the CMS, including an unauthenticated SQL injection, unauthorized access to the editer_objet API, unauthorized author account modification, remote code execution through spip_jobs after SQL injection, code injection in the private area, and SSRF via redirection during remote content retrieval. SPIP said these issues are not mitigated by the SPIP security screen and added hardening measures such as job signing, stricter authorization checks for sensitive account fields, path traversal protections in find_in_path(), improved URL validation, and tighter restrictions on forum comment models.
A separate high-severity flaw, tracked as CVE-2026-66738, affects SPIP versions prior to 4.4.18 when deployed with SQLite. The bug in the /ecrire/?exec=navigation endpoint lets an authenticated user with editor-level access supply crafted array input that bypasses sanitization, escapes an internally quoted PHP string during evaluation, and can result in arbitrary OS command execution; MySQL-backed installations are not affected. SPIP said administrators upgrading without spip_loader must complete a database update through the private area.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-66738 was updated to change the privilege requirement in both CVSS v3.1 and v4.0 from none to low, reflecting that exploitation requires an authenticated editor-level user. The record describes a code injection flaw in SPIP before 4.4.18 affecting SQLite-backed installations via the /ecrire/?exec=navigation endpoint.
SPIP released version 4.4.18 as a critical security update fixing multiple vulnerabilities, including unauthenticated SQL injection, SQLi-driven unauthorized API access and account modification, remote code execution via spip_jobs, code injection in the private area, and SSRF via redirection. The notice also states these issues are not mitigated by the SPIP security screen and includes additional hardening changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.