Summary
- SPIP 4.4.27 addresses RCE, privilege escalation, XSS and injection weaknesses.
- The project says its security screen does not mitigate the affected core flaws.
- Critical Crayons and Simple logs updates need to be installed separately.
SPIP has released version 4.4.27 to address multiple security vulnerabilities, including pre-authentication remote code execution, privilege escalation and weaknesses capable of exposing site secrets.
The French publishing project released the update on 6 October after fixing flaws involving remote code execution before authentication, cross-site scripting, SQLite injection, anonymous HTML uploads and reconstruction of a site secret. Maintainers also warn that the platform’s separate security-screen mechanism does not mitigate the affected core vulnerabilities.
Because the security screen cannot provide an interim layer of protection for this set, affected installations need to move onto a corrected software version rather than relying on the additional filtering mechanism. SPIP identifies 4.4.27 as the relevant stable update after a late bug caused the project to move past 4.4.26.
Two widely used plugins received separate critical fixes alongside the core release. Crayons 3.5.0 addresses SQL injection, unauthenticated upload of malicious documents and unauthorised changes to database fields, including fields that should not normally be editable.
Those weaknesses can create further routes through the application because control over database fields or uploaded content may allow an attacker to extract site secrets, reconstruct weak passwords, gain additional privileges or reach remote code execution. Updating SPIP core alone does not close those plugin-specific paths where Crayons remains installed.
Simple logs 2.3.0, identified by the project as Simplog in its French documentation, fixes arbitrary reading and deletion of files within an installation. SPIP says exploitation can expose site secrets or create conditions in which a site can be reinstalled and a webmaster account created, potentially leading to code execution.
Although the vulnerabilities differ technically, they converge on a common security problem created by content management platforms. Publicly accessible functions operate alongside administrative interfaces, database access, file handling and extension code, allowing one weakness to become more serious when it crosses into another layer.
Pre-authentication flaws are especially significant because an attacker does not need a legitimate account before beginning exploitation. By contrast, weaknesses requiring an authenticated user begin behind an existing access boundary, although privilege escalation can still turn a limited account into substantially broader control.
Plugin architectures extend the same trust model to independently maintained code running inside the application environment. An extension that can write files or alter database content may inherit permissions that give successful exploitation consequences well beyond the feature the plugin was originally intended to provide.
SPIP is used across publishing, organisational and public-facing websites, particularly in French-speaking markets, but the existence of these vulnerabilities does not establish that every installation is exploitable in the same way. Version, configuration and installed plugins determine which attack paths are present.
The project has not reported the newly corrected vulnerabilities as part of an active exploitation campaign. Administrators therefore face a vulnerability-management decision rather than evidence that an affected site should automatically be treated as compromised.
Where Crayons or Simple logs is installed, the core and plugin updates need to be considered together. Moving to SPIP 4.4.27 while leaving a vulnerable plugin unchanged would close the core issues while preserving a separate route through the same application environment.





