PT-2026-21859 · WordPress · Spip Tickets Plugin

Valentin Lobstein

+1

·

Publicado

2026-02-25

·

Atualizado

2026-03-02

·

CVE-2026-27744

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SPIP tickets plugin versions prior to 4.3.3
Description The SPIP tickets plugin is affected by a remote code execution issue. An unauthenticated attacker can execute code on the web server through crafted content injection. The plugin appends untrusted request parameters into HTML that is rendered by a template using unfiltered environment rendering (#ENV), disabling SPIP output filtering. This allows the attacker to inject content that is evaluated by SPIP’s template processing chain.
Recommendations Update the SPIP tickets plugin to version 4.3.3 or later.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27744

Produtos afetados

Spip Tickets Plugin