It was discovered that SPIP, a website engine for publishing, would allow a malicious user to SQL injection attacks, or bypass authorization access.
For the stable distribution (bullseye), this problem has been fixed in version 3.2.11-3+deb11u6.
We recommend that you upgrade your spip packages.
For the detailed security status of spip please refer to its security tracker page at: \ https://security-tracker.debian.org/tracker/spip