# SPIP CMS Patches Multiple Vulnerabilities

Published: 2026-07-07 · Severity: medium · Sectors: media
Canonical: https://vorant.io/reports/ce2e9d64-8168-518d-90a3-f4d6dfc1189e/spip-cms-patches-multiple-vulnerabilities

> Multiple vulnerabilities in SPIP CMS before version 4.4.16 allow SQL injection, XSS, and data confidentiality breaches.

CERT-FR issued an advisory regarding multiple vulnerabilities discovered in SPIP, a French content management system, affecting all versions prior to 4.4.16. The flaws include SQL injection, reflected/indirect cross-site scripting (XSS), and issues that could lead to unauthorized disclosure of confidential data.

No evidence of active exploitation is mentioned in the advisory. SPIP has released version 4.4.16 to address these issues, and administrators are advised to consult the vendor's security bulletin and apply the available patches promptly.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0838

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ce2e9d64-8168-518d-90a3-f4d6dfc1189e/spip-cms-patches-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
