• Tenable
  • CVEs
  • Settings
    Links
    Tenable Cloud Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Plugins
  • Overview
  • Plugins Pipeline
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • Tenable OT Security Families
  • Tenable Cloud Security Families
  • Tenable Self-Hosted Container Security Families
  • About Plugin Families
  • Release Notes
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
    • Links
    • Tenable Cloud
    • Tenable Community & Support
    • Tenable University
    • Settings
    • Severity
    • Theme
Detections
  • Plugins
  • Overview
  • Plugins Pipeline
  • Release Notes
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • Tenable OT Security Families
  • Tenable Cloud Security Families
  • Tenable Self-Hosted Container Security Families
  • About Plugin Families
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
Analytics
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
  1. CVEs
  2. CVE-2023-27372
  1. CVEs

CVE-2023-27372

critical
  • Information
  • CPEs
  • Plugins

Description

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

References

https://github.com/scriniariii/CVE-2023-27372

https://github.com/Chocapikk/CVE-2025-71243

https://github.com/inviewp/CVE-2023-27372

https://github.com/ShadowByte1/CVES

https://github.com/thatformat/Hvv2023

https://github.com/GREENHAT7/Hvv2023

https://github.com/izzz0/CVE-2023-27372-POC

https://github.com/tucommenceapousser/CVE-2023-27372

https://www.debian.org/security/2023/dsa-5367

https://packetstorm.news/files/id/173044

https://packetstorm.news/files/id/171921

https://git.spip.net/spip/spip/commit/96fbeb38711c6706e62457f2b732a652a04a409d

https://git.spip.net/spip/spip/commit/5aedf49b89415a4df3eb775eee3801a2b4b88266

https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-2-1-SPIP-4-1-8-SPIP-4-0-10-et.html

http://packetstormsecurity.com/files/173044/SPIP-4.2.1-Remote-Code-Execution.html

http://packetstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.html

Details

Source: Mitre, NVD

Published: 2023-02-28

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99682

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2026 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance