SPIP vendor intelligence

SPIP Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting SPIP products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEV feed
Total KEVs
4
Known exploited vulnerabilities affecting SPIP products
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
SPIP KEVs with sensor-observed exploitation activity

The catalog gap matters for SPIP exposure

All four exploited SPIP vulnerabilities tracked by Previdian are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.

0%
Covered by CISA
100%
Beyond CISA
1
Product families

Attested SPIP vulnerabilities

4 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-77806

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...

SPIP High Beyond CISA 21 Aug 2026
CVE-2026-77647

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...

SPIP High Beyond CISA 20 Aug 2026
CVE-2024-7954

SPIP porte_plume Plugin Arbitrary PHP Execution

SPIP High Beyond CISA 26 Jun 2025
CVE-2009-3041

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which...

SPIP High Beyond CISA 01 Sep 2009

Showing 4 of 4 on this page (4 SPIP known exploited vulnerabilities).

Recurring weakness patterns

Control, validation, and permissions, privileges, and access controls account for four mapped occurrences across this SPIP KEV portfolio.

Browse all KEVs →