SPIP Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for SPIP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
2
In CISA KEV
0
Beyond CISA KEV
2
Sensor Observed
0
Virtual Patch Available
0
SPIP KEVs Added by Year
Loading...
2 SPIP KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-7954
SPIP porte_plume Plugin Arbitrary PHP Execution |
SPIP | High | Not in CISA | 26 Jun 2025 |
|
CVE-2009-3041
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which... |
SPIP | High | Not in CISA | 01 Sep 2009 |
Common Vulnerability Classes (CWE)
- CWE-1286 — Improper Validation of Syntactic Correctness of Input 1
- CWE-264 — Permissions, Privileges, and Access Controls 1
- CWE-95 — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology