Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
SPIP interface_traduction_objets Plugin Allows Remote Code Execution
CVE-2026-27745
Summary
A security flaw in the SPIP interface_traduction_objets plugin lets an authenticated user with editor-level access inject and execute malicious code on the server. This could allow an attacker to access sensitive data or take control of the server. Update to version 2.2.2 or later to fix the issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| spip | interface_traduction_objets | <= 2.2.2 | – |
Original title
The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untru...
Original description
The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output filtering. Because fields prefixed with an underscore bypass protection mechanisms and the hidden content is rendered with filtering disabled, an authenticated attacker with editor-level privileges can inject crafted content that is evaluated through SPIP's template processing chain, resulting in execution of code in the context of the web server.
nvd CVSS3.1
8.8
nvd CVSS4.0
8.7
Vulnerability type
CWE-94
Code Injection
- https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-10.html Release Notes
- https://chocapikk.com/posts/2026/spip-plugins-vulnerabilities/ Third Party Advisory
- https://git.spip.net/spip-contrib-extensions/interface_traduction_objets/-/commi... Patch
- https://plugins.spip.net/interface_traduction_objets Product
- https://www.vulncheck.com/advisories/spip-interface-traduction-objets-authentica... Third Party Advisory
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026