PT-2026-20848 · Spip · Spip

Dorian Piette

·

Published

2026-02-19

·

Updated

2026-02-23

·

CVE-2025-71250

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.4.9
Description SPIP versions prior to 4.4.9 contain an insecure deserialization flaw. This issue affects the public area through the table valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content can trigger arbitrary object instantiation and potentially achieve remote code execution. The use of serialized data in these components has been deprecated and will be removed in SPIP 5.
Recommendations Update to SPIP version 4.4.9 or later.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-71250

Affected Products

Spip