CVE-2026-72708 is an unauthenticated blind SQL injection vulnerability affecting SPIP versions before 4.4.18. The public sitemap functionality passes attacker-controlled date-filter input through the MySQL escaping routine. Under a specific input pattern—a word character followed by an opening parenthesis—the routine returns a value without escaping it when the target column has a date type. This allows attacker-supplied SQL expressions to be incorporated into the sitemap query, supporting time-based and boolean-based blind data extraction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone Python exploit repository containing one executable, casse-spip.py, plus a README and pinned httpx, typer, and socksio dependencies. It implements a three-CVE SPIP attack chain rather than merely detecting exposure. It first probes /sitemap.xml and its spip.php fallback, then abuses the sitemap annee date criterion for blind unauthenticated SQL injection. The script extracts the 32-character alea_ephemere secret using either a <loc>-count boolean oracle or a SLEEP-based timing oracle, with SQL-expression variants for MySQL and SQLite. The recovered secret is used to forge SPIP anonymous-action nonces. One chain invokes editer_auteur to dump an author's login/password hash and replace the password, with a restore-hash option to revert it. The RCE chain uses editer_objet mass assignment to write a spip_jobs entry, invokes syndiquer_site and cron to run it, and retrieves command output from a randomized file under IMG/. The supplied command is configurable through --exploit/-c, so the primary impact is unauthenticated arbitrary command execution on vulnerable SPIP instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-accessible, low-complexity vulnerability with no required privileges or user interaction, affecting Canonical Ubuntu Linux LTS releases 16.04 through 26.04. The supplied CVSS v3 vector indicates high confidentiality impact and no stated integrity or availability impact.
An unauthenticated time-based and boolean-based blind SQL injection vulnerability in SPIP's public sitemap endpoint. A flaw in spip_mysql_cite() can leave certain date-column values unescaped, allowing crafted annee parameter values to inject SQL and potentially disclose arbitrary database contents, including the alea_ephemere secret used to sign action nonces.
An unauthenticated network-reachable blind SQL injection in SPIP versions before 4.4.18. The public sitemap's annee parameter can trigger faulty escaping for date columns, enabling time- or boolean-based extraction of arbitrary database content, including the alea_ephemere secret used to sign action nonces.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.