
CVE-2026-27743 SQL Injection in SPIP Referer Spam Plugin Before 1.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27743
Post summary
A SQL injection vulnerability (CVE-2026-27743) exists in SPIP Referer Spam Plugin versions prior to 1.3.0.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE clauses without input validation or parameterization. The endpoints do not enforce authorization checks and do not use SPIP action protections such as securiser_action(), allowing remote attackers to execute arbitrary SQL queries.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-02-25 | 4 | Disclosure3Patch1 |
| 2026-03-02 | 1 | Disclosure1 |

CVE-2026-27743 SQL Injection in SPIP Referer Spam Plugin Before 1.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27743
Post summary
A SQL injection vulnerability (CVE-2026-27743) exists in SPIP Referer Spam Plugin versions prior to 1.3.0.

CVE-2026-27743 (CVSS:9.3, CRITICAL) is Analyzed. The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the refer..https://nvd.nist.gov/vuln/detail/CVE-2026-27743 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
Post summary
The post announces a critical SQL injection vulnerability (CVE‑2026‑27743) in the SPIP referer_spam plugin, providing CVSS details and linking to the NVD entry.

🔴 CVE-2026-27743 - Critical The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The ha... https://www.thehackerwire.com/vulnerability/CVE-2026-27743/ https://t.co/KyrbL0FKOG
Post summary
The post announces a critical unauthenticated SQL injection vulnerability in SPIP's referer_spam plugin (versions <1.3.0), detailing affected action handlers but not providing PoC or patch info.

CVE-2026-27743 The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer act… https://www.cve.org/CVERecord?id=CVE-2026-27743
Post summary
The CVE-2026-27743 entry reports an unauthenticated SQL injection in the SPIP referer_spam plugin (versions <1.3.0), but provides no PoC, exploit code, or patch details.

🚨 CRITICAL: CVE-2026-27743 in SPIP referer_spam lets unauth'd attackers run SQL via GET requests — no exploit yet, but risk is high. PATCH to 1.3.0+ ASAP to safeguard data! 🔒 https://radar.offseq.com/threat/cve-2026-27743-cwe-89-improper-neutralization-of-s-0723b396 #OffSeq #S... https://t.co/gvIXnSo9Eo
Post summary
CVE-2026-27743 is a critical SQL injection in SPIP’s referer_spam module; no exploit exists yet, but the advisory urges applying patch 1.3.0+ immediately.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | spip | referer_spam | - | - | - |