SPIP 3.0.9, 2.1.22 and 2.0.23 fixed a privilege escalation vulerability,
where an user can take editorial control on the site. Upstream announce
is at [1] and the upstream commit fixing it is [2].
I'm CC'ing David Prvot, Debian maintainer for spip (there does not seem
to be a english translation of the announce available right now).
[1] ttp://contrib.spip.net/SPIP-3-0-9-2-1-22-2-0-23-corrections-de-bug-et-faille?lang=fr
[2] http://core.spip.org/projects/spip/repository/revisions/20541
[3] http://bugs.debian.org/709674