LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-27745

CVE-2026-27745 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: February 26, 2026

SPIP interface_traduction_objets - Remote Code Execution

Published: February 25, 2026Updated: February 26, 2026Remote Exploitable

Overview

SPIP interface_traduction_objets plugin < 4.3.3 contains an authenticated remote code execution caused by untrusted request data in hidden form fields rendered without output filtering, letting authenticated editors execute code via template processing.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 13.8%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers with editor privileges can execute arbitrary code on the web server, potentially compromising the entire system.

Mitigation

Upgrade to version 4.3.3 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Feb 25, 2026

🟠 CVE-2026-27745 - High (8.8) The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that i... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-27745/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Feb 25, 2026

🟠 CVE-2026-27745 - High (8.8) The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that i... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-27745/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-27745
Severity
High
CVSS Score
8.8
Type
template_injection
Status
unconfirmed
EPSS
13.8%
Social Posts
2

CWE

  • CWE-94

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

13.8%Probability of exploitation in the next 30 days