PT-2026-20848 · Spip · Spip
Dorian Piette
·
Published
2026-02-19
·
Updated
2026-02-23
·
CVE-2025-71250
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SPIP versions prior to 4.4.9
Description
SPIP versions prior to 4.4.9 contain an insecure deserialization flaw. This issue affects the public area through the
table valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content can trigger arbitrary object instantiation and potentially achieve remote code execution. The use of serialized data in these components has been deprecated and will be removed in SPIP 5.Recommendations
Update to SPIP version 4.4.9 or later.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spip