SPIP Tickets Plugin Unauthenticated Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the SPIP tickets plugin, affecting versions prior to 4.3.3. The issue arises in the forum preview handling for public ticket pages, where the plugin improperly processes untrusted request parameters. These parameters are injected into HTML and rendered using an unfiltered environment, disabling SPIP's output filtering. This vulnerability allows an unauthenticated attacker to inject malicious content that is executed through SPIP's template processing, running code in the context of the web server.

Impact

Exploitation of this vulnerability allows for unauthenticated remote code execution on the server where the SPIP tickets plugin is installed.

Remediation

Users can update to SPIP tickets plugin version 4.3.3 or later to address this vulnerability.

Added: Feb 25, 2026, 4:20 AM
Updated: Feb 25, 2026, 4:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.1
remediation
0.0
relevance
3.4
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.