CVE-2026-77806
SPIP90/100
exploitation likelihood
CVSS9.8
EPSS1.3%
VulnCheck KEVEXPLOITED
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 9.8
Public PoC / Exploit3
Defensive review only — these references demonstrate exploitability.
References4