Medium severity6.1NVD Advisory· Published Aug 13, 2026
CVE-2026-73628
CVE-2026-73628
Description
Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1.
Affected products
1- Range: >=2.3.5 <=2.6.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.