Vulnerabilities
CVE-2026-22206 - SPIP < 4.4.10 SQL Injection RCE via Union & PHP Tags
CVE ID : CVE-2026-22206 Published : Feb. 26, 2026, 9:28 p.m. | 37 minutes ago Description : SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
PHP
Impact:
SQL injection