CVE-2026-22205: high-severity vulnerability in SPIP
SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive internal data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
SPIP · SPIPRelated CVEs — SPIP
In the same product, most dangerous first.
CVE-2024-8517CRITICALSPIP Bigup Multipart File Upload OS Command InjectionEPSS 94.6%CVE-2024-7954CRITICALSPIP porte_plume Plugin Arbitrary PHP ExecutionEPSS 90.1%CVE-2026-77806CRITICALCVE-2026-77806EPSS 4.5%CVE-2026-77647CRITICALCVE-2026-77647EPSS 2.3%CVE-2026-72710CRITICALSPIP < 4.4.18 RCE via editer_objet.php Job Queue InjectionEPSS 1.1%CVE-2026-8429HIGHSPIP < 4.4.14 Remote Code Execution via Private SpaceEPSS 0.9%