CVE-2026-72708: SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter

Published Sep 11, 2026
·
Updated

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spipmysqlcite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis. Attackers can supply a crafted value such as a time-based payload through the annee parameter in squelettes-dist/sitemap.xml.html to embed arbitrary SQL directly into the generated query, enabling time-based and boolean-based blind SQL injection that can expose arbitrary database content including the aleaephemere secret used to sign action nonces.

Affected Software

1 affected component
Spip SPIP<4.4.18

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SPIP to a version that resolves this vulnerability.

    Fixed in 4.4.18
  2. Compensating control

    Restrict access to the public sitemap endpoint (squelettes-dist/sitemap.xml.html and associated sitemap functionality) so unauthenticated clients cannot reach it, until SPIP is upgraded to 4.4.18 or later.

Event History

Sep 11, 2026
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

SPIP installations running versions before 4.4.18 are affected when the public sitemap endpoint is reachable. The vulnerable input is the annee parameter processed by squelettes-dist/sitemap.xml.html.

2

Does an attacker need an account or user interaction?

No. The issue is exploitable without authentication and does not require user interaction; an attacker can send a crafted annee parameter to the public endpoint.

3

What could an attacker obtain through this issue?

The blind SQL injection can be used to extract arbitrary database content through time-based or boolean-based techniques. This may include the alea_ephemere secret used to sign action nonces.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203