HarborGuard / CVE
Back to search
HIGHCVE-2026-22206Published Modified CNA VulnCheck

CVE-2026-22206: SPIP < 4.4.10 SQL Injection RCE via Union & PHP Tags

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
4.4.10
Affected Products
1

Fix available

4.4.10
Patch commits
Affected packages
  • SPIP / SPIP
    < 4.4.10 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N