Serendipity
Sign in to watchby Serendipity
CVEs (7)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2011-4090 | 0.03 | — | 0.01 | Nov 26, 2019 | Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation. | ||
| CVE-2024-58282 | 0.00 | — | 0.00 | Dec 10, 2025 | Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrary system command execution on the web server. | ||
| CVE-2008-1476 | 0.00 | — | 0.01 | Mar 24, 2008 | Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to received trackbacks. | ||
| CVE-2007-6390 | 0.00 | — | 0.00 | Dec 17, 2007 | Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page. | ||
| CVE-2007-4282 | 0.00 | — | 0.00 | Aug 9, 2007 | The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked. | ||
| CVE-2007-1326 | 0.00 | — | 0.01 | Mar 7, 2007 | SQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[multiCat][] parameter. | ||
| CVE-2006-5499 | 0.00 | — | 0.03 | Oct 25, 2006 | Multiple cross-site scripting (XSS) vulnerabilities in Serendipity (s9y) 1.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the media manager administration page. |