What is CVE-2026-66738?
A code injection vulnerability exists in SQLite-backed SPIP installations prior to version 4.4.18. The navigation menu endpoint improperly handles array-typed user input, bypassing sanitization and allowing PHP code execution. Users should upgrade to SPIP 4.4.18 or later to mitigate this issue.
Azərbaycanca: SPIP platformasının 4.4.18 versiyasından əvvəlki SQLite dəstəkli qurğularında kod inyeksiyası zəifliyi aşkar edilib. Naviqasiya menyusu funksiyası massiv tipli istifadəçi girişini düzgün işləməyərək PHP kodunun icrasına imkan yaradır. Bu problemi aradan qaldırmaq üçün SPIP-i dərhal 4.4.18 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What version should I upgrade to if my SPIP installation uses SQLite?
You should upgrade to SPIP 4.4.18 or later to mitigate the code injection vulnerability in SQLite-backed installations.
Which SPIP function can be exploited through this vulnerability?
The vulnerability can be exploited through the navigation menu endpoint, which improperly handles array-typed user input.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.