CVE-2026-72708 | SPIP up to 4.4.17 Sitemap Endpoint ecrire/req/mysql.php spip_mysql_cite annee sql injection
A vulnerability, which was classified as critical, was found in SPIP up to 4.4.17. The affected element is the function spip_mysql_cite of the file ecrire/req/mysql.php of the component Sitemap Endpoint. The manipulation of the argument annee results in sql injection.
This vulnerability is cataloged as CVE-2026-72708. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More