Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

SPIP 4.4.8 and earlier may allow unauthorized server access

CVE-2026-27472
Summary

A security flaw in SPIP versions 4.4.8 and earlier allows an attacker who has access to the private area to make the server access unauthorized destinations. This could potentially allow the attacker to access sensitive information or take control of internal systems. Update to SPIP 4.4.9 to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
spip spip > 4.4.0 , <= 4.4.9 –
Original title
SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL ...
Original description
SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated attacker to make the server issue requests to arbitrary internal or external destinations. This vulnerability is not mitigated by the SPIP security screen.
nvd CVSS3.1 4.3
nvd CVSS4.0 5.3
Vulnerability type
CWE-918 Server-Side Request Forgery (SSRF)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026