CVE-2026-72708: SPIP < 4.4.18 Unauthenticated Blind SQL Injection via sitemap.xml.html
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which bypasses escaping for date-type columns across MySQL, SQLite, and PostgreSQL backends. Attackers can exploit the always-present sitemap.xml.html template's annee criterion to embed unescaped time-based or boolean payloads into database queries, enabling extraction of arbitrary database content including the aleaephemere secret used to sign SPIP action nonces.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SPIPto a version that resolves this vulnerability.Fixed in 4.4.18 - Compensating control
Restrict access to SPIP endpoints that accept the annee parameter (and sitemap.xml.html) to unauthenticated clients where possible, to reduce exposure to the unauthenticated blind SQL injection.
Event History
Frequently Asked Questions
Which deployments are exposed?
SPIP installations running versions before 4.4.18 are affected when the public sitemap endpoint is reachable. The vulnerable input is the annee parameter processed by squelettes-dist/sitemap.xml.html.
Does an attacker need an account or user interaction?
No. The issue is exploitable without authentication and does not require user interaction; an attacker can send a crafted annee parameter to the public endpoint.
What could an attacker obtain through this issue?
The blind SQL injection can be used to extract arbitrary database content through time-based or boolean-based techniques. This may include the alea_ephemere secret used to sign action nonces.