SPIP Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for SPIP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

0

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

SPIP KEVs Added by Year

Loading...

2 SPIP KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2024-7954

SPIP porte_plume Plugin Arbitrary PHP Execution

High Not in CISA 26 Jun 2025
CVE-2009-3041

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which...

High Not in CISA 01 Sep 2009

Common Vulnerability Classes (CWE)

  • CWE-1286 — Improper Validation of Syntactic Correctness of Input 1
  • CWE-264 — Permissions, Privileges, and Access Controls 1
  • CWE-95 — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology