Critical SPIP plugin bug lets anyone edit your site's database fields without logging in
A near-maximum severity score sounds terrifying, but the catch is in how niche the affected software actually is.
A newly disclosed vulnerability in a plugin for the French content management system SPIP has earned a CVSS score of 9.8 out of 10 — about as bad as these ratings get. The catch? You’ve probably never installed SPIP, let alone its “Crayons” add-on, so this is very much a case of checking who’s actually exposed before panicking.
What the bug actually does
CVE-2026-104070 affects Crayons, a plugin that lets logged-in editors make quick edits to a SPIP-powered site directly from its public-facing pages. According to NVD’s entry, versions before 3.5.0 are missing a proper authorisation check. Normally, requests that change data on the site have to carry a “secu_” anti-forgery token proving the request came from a genuine, logged-in session. Crayons, it turns out, didn’t always check for that token — meaning an attacker who never logs in at all could still send requests that alter arbitrary “editable” fields in the site’s database.
The SPIP project’s own blog post goes further than the bare NVD summary, describing the underlying fix in Crayons 3.5.0 as patching several critical issues together: SQL injection, unauthenticated uploading of malicious files, and unauthenticated tampering with database fields — including ones that shouldn’t be editable at all. The SPIP team says chaining these together could, in theory, lead to weak-password resets, privilege escalation, extraction of the site’s secret keys, and ultimately full remote code execution. That’s the realistic worst case being described, not a confirmed incident.
A second plugin, Simple Logs, got its own critical patch (to version 2.3.0) in the same announcement, fixing an unrelated flaw that let attackers read or delete arbitrary files — again, potentially enabling a full site takeover. It’s a separate vulnerability, bundled into the same release notice because both landed on the same day.
So who is actually at risk
This only matters if you run a SPIP-based website with the Crayons plugin installed and haven’t updated. SPIP is a long-running open-source CMS popular mainly in French-language publishing circles — it’s not WordPress, and it’s not something most UK readers or businesses will have anywhere near their stack. SPIP’s own plugin directory lists 739 sites currently using Crayons, though that figure comes from self-reported usage statistics on SPIP’s plugin hub, so the real-world number running older, vulnerable versions could be higher or lower than that count suggests.
Neither NVD nor the SPIP blog provides any evidence that this flaw is being actively exploited — there’s no indication of in-the-wild attacks at the time of publication. This is a responsibly disclosed bug with a patch already available, not a breach in progress.
What to do about it
If you administer a SPIP site, update Crayons to 3.5.0 and Simple Logs to 2.3.0 immediately, alongside the underlying SPIP core update to version 4.4.27, which the project is bundling with this advisory. If you don’t run SPIP, there is nothing to do here.
The takeaway
A 9.8 CVSS score grabs attention, and the vulnerability itself is genuinely serious for the handful of sites affected. But severity scores measure technical impact, not how many people are actually exposed. For the vast majority of readers, this is a reminder to patch promptly if you run niche CMS software — not a reason to lose sleep over your own accounts.