CVE-2026-22206

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-26 21:28

Updated : 2026-03-02 15:58


NVD link : CVE-2026-22206

Mitre link : CVE-2026-22206

CVE.ORG link : CVE-2026-22206


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')