High severity8.8OSV Advisory· Published Dec 17, 2025· Updated Jun 17, 2026
CVE-2023-53933
CVE-2023-53933
Description
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2.4.0
- Range: 2.1-beta1, 2.1-beta2, 2.1-beta3, …
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51372nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/serendipity-authenticated-remote-code-execution-via-file-uploadnvdExploitThird Party Advisory
- docs.s9y.orgnvdProduct
News mentions
0No linked articles in our index yet.