Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can trigger arbitrary object instantiation and potentially achieve code execution. The use of serialized data in these components has been deprecated and will be removed in SPIP 5. This vulnerability is not mitigated by the SPIP security screen. | |
| Title | SPIP < 4.4.9 Insecure Deserialization | |
| First Time appeared |
Spip
Spip spip |
|
| CPEs | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spip
Spip spip |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-20T20:10:28.445Z
Reserved: 2026-02-19T18:34:45.842Z
Link: CVE-2026-27475
Updated: 2026-02-20T20:10:22.201Z
Status : Awaiting Analysis
Published: 2026-02-19T19:22:30.720
Modified: 2026-02-20T13:49:47.623
Link: CVE-2026-27475
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:05:55Z
No weakness.