CVE List

CVE-2022-28960

Critical 8.8

A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

Published May 19, 2022.

Affected software

Get alerts for Spip Spip

Reference links