Metasploit Project[verified]@metasploitExploit
Metasploit released a new module delivering an unauthenticated RCE for SPIP Saisies (CVE-2025-71243), confirming functional exploit code is now available.
Chocapikk 🤘🏻[verified]@Chocapikk_Disclosure
The author reversed CVE‑2025‑71243 in SPIP’s Saisies plugin and identified five additional template injection vulnerabilities across four low‑adoption plugins, all sharing an eval() chain pattern.
Chocapikk 🤘🏻[verified]@Chocapikk_PoC
The advisory announces CVE-2025-71243, a RCE in the SPIP Saisies plugin, and releases a PoC and exploit code via GitHub, but does not report active exploitation or provide patch details, while detailing the unsanitized input vulnerability.
Security Arsenal, LLC[verified]@SecurityAr58409General
The tweet simply mentions CVE-2025-71243 and links to a blog post, without providing any proof‑of‑concept, exploit details, active exploitation evidence, or remediation information.
CVETodo[verified]@CveTodoGeneral
The post highlights CVE-2025-71243 as a remote‑code‑execution flaw that allows arbitrary PHP code execution via malicious data, but provides no evidence of active exploitation, PoC, or patch information.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces a critical RCE vulnerability in SPIP Saisies plugin versions 5.4.0‑5.11.0 and links to a ProjectDiscovery resource for further detail.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new remote code execution vulnerability has been disclosed in the SPIP Saisies plugin versions 5.4.0‑5.11.0, identified as CVE‑2025‑71243.
The Hacker Wire@TheHackerWireDisclosure
The Saisies plugin for SPIP (versions 5.4.0‑5.11.0) contains a critical RCE vulnerability. No PoC, exploit code, patch, or active exploitation details are provided.