CVE 8.8 HIGH

SPIP < 4.4.14 Remote Code Execution via Private Space_CVE-2026-8429

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability to achieve code execution that bypasses the SPIP security screen protections.

Basic Information

ID CVE-2026-8429
Source VulnCheck
Published May 12, 2026 at 18:32
Modified May 12, 2026 at 19:41

Affected Product

Vendor SPIP
Product SPIP
Affected Versions SPIP SPIP 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.