CVE-2026-22206
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
Vendor
Product
CWE
Yayın Tarihi
2026-02-26 21:28:52
Güncelleme
2026-03-02 15:58:07
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-