PT-2026-20841 · Spip+1 · Spip+1

Openstudio

·

Published

2026-02-19

·

Updated

2026-04-15

·

CVE-2025-71243

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SPIP Saisies plugin versions 5.4.0 through 5.11.0
Description The 'Saisies pour formulaire' (Saisies) plugin for SPIP contains a critical Remote Code Execution (RCE) issue. An attacker can exploit this issue to execute arbitrary code on the server. The vulnerability is due to a template injection pattern, potentially involving an eval() chain, with different entry points identified in multiple plugins.
Recommendations Update to version 5.11.1 or later.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-71243

Affected Products

Spip
Saisies Pour Formulaire