Skip to finding
important · Web applications

Two newly disclosed SPIP core flaws permit pre-authentication server-side code execution.

Affects

SPIP, an open-source content-management system running public websites on PHP web servers

SPIP 4.4.22 fixes both paths, and the project's separate security-screen mechanism does not cover them.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026