SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated attacker to make the server issue requests to arbitrary internal or external destinations. This vulnerability is not mitigated by the SPIP security screen.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27472.json",
"cna_assigner": "VulnCheck"
}{
"cpe": "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "4.4.0"
},
{
"fixed": "4.4.9"
}
],
"source": [
"AFFECTED_FIELD",
"CPE_RANGE"
]
}