CVE-2026-104070 - SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE
CVE ID :CVE-2026-104070 Published : Oct. 6, 2026, 4:16 p.m. | 1 hour, 12 minutes ago Description :The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_...