CVE-2025-71243Disclosure(spip / saisies)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for spip saisies systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • saisies

Threat summary

  • Public PoC and exploit tooling are both present
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 4 mentions (2026-02-19); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
saisies

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-02-19: 4Mentions · 2026-02-25: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-03-13: 1Exploit Tool / Code · 2026-02-19: 1Exploit Tool / Code · 2026-03-13: 1Technical Details · 2026-02-19: 4Technical Details · 2026-02-25: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 102-1902-2503-1103-1304-15
Signal classification4 categories
Disclosure
450.0%
General
225.0%
PoC
112.5%
Exploit
112.5%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-194
Disclosure2General1PoC1
2026-02-251
Disclosure1
2026-03-111
Disclosure1
2026-03-131
Exploit1
2026-04-151
General1
Full discourse8 posts
  • Metasploit Project@metasploit
    Exploit

    No bad luck here! 🍀 The Metasploit weekly wrapup is live with 3 new modules: LeakIX Search, Linux RC4 payload packer, and an unauthenticated RCE for SPIP Saisies (CVE-2025-71243). Plus, check out Metasploit Pro 5.0.0! Read the full details: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-03-13-2026/ #Metasploit

    Post summary

    Metasploit released a new module delivering an unauthenticated RCE for SPIP Saisies (CVE-2025-71243), confirming functional exploit code is now available.

    01013293.7K
    252.8K followersView on X
  • Chocapikk 🤘🏻@Chocapikk_
    Disclosure

    After reversing CVE-2025-71243 in SPIP's Saisies plugin, I audited other SPIP plugins for the same template injection pattern. Found 5 more vulnerabilities across 4 plugins - same eval() chain, different entry points. Low-adoption plugins, but the patterns are worth documenting. https://chocapikk.com/posts/2026/spip-plugins-vulnerabilities/

    Post summary

    The author reversed CVE‑2025‑71243 in SPIP’s Saisies plugin and identified five additional template injection vulnerabilities across four low‑adoption plugins, all sharing an eval() chain pattern.

    05135102.3K
    3.9K followersView on X
  • Chocapikk 🤘🏻@Chocapikk_
    PoC

    CVE-2025-71243 - SPIP Saisies Plugin RCE Advisory dropped today, PoC ready 30 minutes later. Full AI-assisted reversal from patch diff to confirmed RCE. Same exploitation pattern as CVE-2023-27372 - unsanitized input into SPIP's template engine with interdire_scripts=false. Two years later. Discovery: OpenStudio Writeup: https://chocapikk.com/posts/2026/spip-saisies-rce/ PoC: https://github.com/Chocapikk/CVE-2025-71243

    Post summary

    The advisory announces CVE-2025-71243, a RCE in the SPIP Saisies plugin, and releases a PoC and exploit code via GitHub, but does not report active exploitation or provide patch details, while detailing the unsanitized input vulnerability.

    2402652.0K
    3.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-71243 - critical 🚨 SPIP Saisies - Remote Code Execution > SPIP Saisies plugin 5.4.0 through 5.11.0 contains a remote code execution caused by a... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-71243 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical RCE vulnerability in SPIP Saisies plugin versions 5.4.0‑5.11.0 and links to a ProjectDiscovery resource for further detail.

    00021258
    902 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71243 Remote Code Execution Vulnerability in SPIP Saisies Plugin 5.4.0-5.11.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71243

    Post summary

    A new remote code execution vulnerability has been disclosed in the SPIP Saisies plugin versions 5.4.0‑5.11.0, identified as CVE‑2025‑71243.

    0001047
    4.0K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity Defending Against CVE-2025-71243 and Emerging Linux Evasion Techniques "In the cybersecurity landscape, tools used by penetration testers often provide…" 🔗 https://securityarsenal.com/blog/defending-against-cve-2025-71243-and-emerging-linux-evasion-techniques #CyberSecurity #ThreatIntel #penetrationtesting #redteam #offensivesecurity

    Post summary

    The tweet simply mentions CVE-2025-71243 and links to a blog post, without providing any proof‑of‑concept, exploit details, active exploitation evidence, or remediation information.

    00000135
    10 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-71243 - Critical The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerabi... https://www.thehackerwire.com/vulnerability/CVE-2025-71243/ https://t.co/hDv5Eay78p

    Post summary

    The Saisies plugin for SPIP (versions 5.4.0‑5.11.0) contains a critical RCE vulnerability. No PoC, exploit code, patch, or active exploitation details are provided.

    0000055
    112 followersView on X
  • CVETodo@CveTodo
    General

    Given the nature of RCE vulnerabilities, the attacker may craft a malicious payload (e.g., specially formatted data or scripts) that, when processed by the plugin, results in the execution of arbitrary PHP code on the server. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2025-71243

    Post summary

    The post highlights CVE-2025-71243 as a remote‑code‑execution flaw that allows arbitrary PHP code execution via malicious data, but provides no evidence of active exploitation, PoC, or patch information.

    0000029
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appspipsaisies-spip-

Explore more