Updated spip packages has been released for both Debian GNU/Linux 8 and 9 to address several vulnerabilities, resulting in cross-site scripting and PHP injection
Spip Security Update for Debian 8 and 9