Skip to content
Critical SQL Injection Vulnerability in SPIP CMS Exposed

Critical SQL Injection Vulnerability in SPIP CMS Exposed

First seen 12 Sep 2026, 00:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 12, 2026 at 02:11 UTC
  • CVE-2026-72708 allows unauthenticated SQL injection in SPIP CMS.
  • Exploitation can expose sensitive data without user interaction.
  • Immediate patching and monitoring are critical for affected sites.

A critical unauthenticated blind SQL injection vulnerability (CVE-2026-72708) has been identified in SPIP versions prior to 4.4.18. This vulnerability affects the public sitemap endpoint, allowing attackers to exploit the 'annee' parameter to execute arbitrary SQL queries. The flaw can lead to the exposure of sensitive database information, including application secrets. Internet-facing deployments of SPIP, particularly those in public sectors, media, and shared hosting environments, are at high risk. Attackers can automate the exploitation process without requiring authentication or user interaction. Immediate action is recommended, including applying the vendor's security update and reviewing web logs for unusual activity. The vulnerability was published on September 11, 2026, and is considered urgent for affected organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
CVE-2026-72708 published
SPIP disclosed a critical SQL injection vulnerability affecting versions before 4.4.18.
Redpacketsecurity
2026-09-12
Vulnerability awareness raised
Vulncheck published an advisory on the SPIP SQL injection vulnerability, emphasizing its impact.
www.vulncheck.com

More articles in this cluster (4)

Following this threat?

Track CVE-2026-72708 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed