CVE-2026-72708: SPIP < 4.4.18 Unauthenticated Blind SQL Injection via sitemap.xml.html

Published Sep 11, 2026
·
Updated

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which bypasses escaping for date-type columns across MySQL, SQLite, and PostgreSQL backends. Attackers can exploit the always-present sitemap.xml.html template's annee criterion to embed unescaped time-based or boolean payloads into database queries, enabling extraction of arbitrary database content including the aleaephemere secret used to sign SPIP action nonces.

Affected Software

1 affected component
Spip SPIP<4.4.18

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SPIP to a version that resolves this vulnerability.

    Fixed in 4.4.18
  2. Compensating control

    Restrict access to SPIP endpoints that accept the annee parameter (and sitemap.xml.html) to unauthenticated clients where possible, to reduce exposure to the unauthenticated blind SQL injection.

Event History

Sep 11, 2026
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

SPIP installations running versions before 4.4.18 are affected when the public sitemap endpoint is reachable. The vulnerable input is the annee parameter processed by squelettes-dist/sitemap.xml.html.

2

Does an attacker need an account or user interaction?

No. The issue is exploitable without authentication and does not require user interaction; an attacker can send a crafted annee parameter to the public endpoint.

3

What could an attacker obtain through this issue?

The blind SQL injection can be used to extract arbitrary database content through time-based or boolean-based techniques. This may include the alea_ephemere secret used to sign action nonces.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203