SPIP vendor intelligence
SPIP Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting SPIP products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 4
- Known exploited vulnerabilities affecting SPIP products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 4
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- SPIP KEVs with sensor-observed exploitation activity
The catalog gap matters for SPIP exposure
Four of the four exploited SPIP vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 1
- Product families
Attested SPIP vulnerabilities
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-77806
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to... |
SPIP | High | Beyond CISA | 21 Aug 2026 |
|
CVE-2026-77647
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to... |
SPIP | High | Beyond CISA | 20 Aug 2026 |
|
CVE-2024-7954
SPIP porte_plume Plugin Arbitrary PHP Execution |
SPIP | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2009-3041
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which... |
SPIP | High | Beyond CISA | 01 Sep 2009 |
No SPIP vulnerabilities match this search or filter.
Showing 4 of 4 SPIP known exploited vulnerabilities.
Recurring weakness patterns
Control, validation, and permissions, privileges, and access controls account for four mapped occurrences across this SPIP KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.