Description
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which bypasses escaping for date-type columns across MySQL, SQLite, and PostgreSQL backends. Attackers can exploit the always-present sitemap.xml.html template's annee criterion to embed unescaped time-based or boolean payloads into database queries, enabling extraction of arbitrary database content including the alea_ephemere secret used to sign SPIP action nonces.
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection exposing sensitive data
Action: Immediate Patch
AI Analysis

Impact

SPIP versions before 4.4.18 contain an unauthenticated blind SQL injection in the SQL escaping layer. Attackers can supply crafted annee parameter values matching a word character followed by an open parenthesis, which bypasses escaping for date‑type columns in MySQL, SQLite, and PostgreSQL. The always‑present sitemap.xml.html template exposes this flaw, enabling injection of unescaped time‑based or boolean payloads. This allows attackers to extract arbitrary database content, including the alea_ephemere secret used to sign SPIP action nonces.

Affected Systems

SPIP content‑management system versions earlier than 4.4.18 are affected.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. Attackers can reach the vulnerable sitemap endpoint over the public network without authentication, making exploitation straightforward. The EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so it has no known public exploit at present. Based on the description the likely attack vector involves crafting the annee parameter value in the sitemap.xml.html request, but the attack does not require authentication.

Generated by OpenCVE AI on September 21, 2026 at 05:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SPIP to 4.4.18 or later to eliminate the flaw.
  • If an upgrade is not immediately possible, restrict public access to the sitemap.xml.html endpoint or block the annee parameter to reduce exposure.
  • Monitor web‑application logs for abnormal SQL query patterns or timing anomalies that may indicate exploitation attempts.

Generated by OpenCVE AI on September 21, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis. Attackers can supply a crafted value such as a time-based payload through the annee parameter in squelettes-dist/sitemap.xml.html to embed arbitrary SQL directly into the generated query, enabling time-based and boolean-based blind SQL injection that can expose arbitrary database content including the alea_ephemere secret used to sign action nonces. SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which bypasses escaping for date-type columns across MySQL, SQLite, and PostgreSQL backends. Attackers can exploit the always-present sitemap.xml.html template's annee criterion to embed unescaped time-based or boolean payloads into database queries, enabling extraction of arbitrary database content including the alea_ephemere secret used to sign SPIP action nonces.
Title SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter SPIP < 4.4.18 Unauthenticated Blind SQL Injection via sitemap.xml.html

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Spip
Spip spip
Vendors & Products Spip
Spip spip

Fri, 11 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis. Attackers can supply a crafted value such as a time-based payload through the annee parameter in squelettes-dist/sitemap.xml.html to embed arbitrary SQL directly into the generated query, enabling time-based and boolean-based blind SQL injection that can expose arbitrary database content including the alea_ephemere secret used to sign action nonces.
Title SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:20:26.790Z

Reserved: 2026-08-10T13:02:52.001Z

Link: CVE-2026-72708

cve-icon Vulnrichment

Updated: 2026-09-15T16:27:31.219Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T17:18:57.197

Modified: 2026-09-15T17:17:24.373

Link: CVE-2026-72708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:15:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')