References https://nvd.nist.gov/vuln/detail/CVE-2023-27372 https://github.com/nuts7/CVE-2023-27372 https://www.exploit-db.com/exploits/51536 https://www.sentinelone.com/vulnerability-database/cve-2023-27372/ https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-2-1-SPIP-4-1-8-SPIP-4-0-10-et.html https://attackerkb.com/topics/G0xQW62Il4/cve-2023-27372 https://github.com/Chocapikk/CVE-2023-27372 https://packetstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.html https://ethicalhacking.uk/cve-2023-27372-remote-code-execution-in-spip/ https://www.rapid7.com/db/vulnerabilities/debian-cve-2023-27372/
Related VulnerabilitiesPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCRMEB /api/remote_register 权限绕过漏洞Apache Kafka UI /smartfilters/testexecutions 代码执行漏洞(CVE-2026-78166)PoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2025-62593: Ray < 2.52.0 - Remote Code Execution全景軟體|CGServiSign - OS Command InjectionPoCCVE-2026-1340: Ivanti EPMM < 12.8.0.0 - Remote Code ExecutionPoCCVE-2026-86218: N-able N-central <2026.3.1.14 - Pre-Authentication Remote Code ExecutionPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoCCVE-2026-2113: tpadmin <= 1.3.12 - Remote Code Execution