Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Serendipity HIGH 7.2
CVE-2026-39971

Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_S…

Fix: 2.6.0+
Fix from $1,950 2026-04-15
Serendipity MEDIUM 6.9
CVE-2026-39963

Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.ph…

Fix: 2.6.0+
Fix from $1,600 2026-04-15
Serendipity HIGH 8.8
CVE-2023-53933

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extensi…

No fix yet
Fix from $1,950 2025-12-17
Serendipity MEDIUM 5.4
CVE-2023-53932

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry…

No fix yet
Fix from $1,600 2025-12-17
Serendipity HIGH 7.2
CVE-2024-58282

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the m…

No fix yet
Fix from $1,950 2025-12-10
Serendipity HIGH 8.8
CVE-2023-31576

An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.

No fix yet
Fix from $1,950 2023-05-16
Serendipity CRITICAL 9.8
CVE-2020-10964

Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This…

Fix: 2.3.4+
Fix from $2,300 2020-03-25
Serendipity Event Freetag MEDIUM 6.1
CVE-2011-3610

A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_even…

Fix: 3.30+
Fix from $1,600 2020-01-22
Serendipity MEDIUM 6.1
CVE-2011-4090

Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.

Fix: 1.6+
Fix from $1,600 2019-11-26
Serendipity CRITICAL 9.8
CVE-2011-1134

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the im…

Fix: 1.5.5+
Fix from $2,300 2019-11-05
Serendipity MEDIUM 6.1
CVE-2011-1133

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugi…

Fix: 1.5.5+
Fix from $1,600 2019-11-05
Serendipity MEDIUM 6.1
CVE-2011-1135

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugin…

Fix: 1.5.5+
Fix from $1,600 2019-11-05
Serendipity CRITICAL 9.8
CVE-2016-10752

serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi…

Mitigation only
Fix from $2,300 2019-05-24
Serendipity MEDIUM 6.1
CVE-2019-11870

Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the template…

Fix: 2.1.5+
Fix from $1,600 2019-05-09
Serendipity MEDIUM 5.4
CVE-2016-10737

Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.

No fix yet
Fix from $1,600 2019-01-16
Serendipity HIGH 7.5
CVE-2017-1000129

Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure

Mitigation only
Fix from $1,950 2017-11-17
Serendipity HIGH 8.8
CVE-2017-8101

There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.

Patch available
Fix from $1,950 2017-04-24
Serendipity MEDIUM 5.4
CVE-2017-8102

Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. Th…

No fix yet
Fix from $1,600 2017-04-24
Serendipity HIGH 8.8
CVE-2017-5609

SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL comm…

Patch available
Fix from $1,950 2017-01-28
Serendipity HIGH 8.8
CVE-2017-5475

comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.

Fix: after 2.0.5
Fix from $1,950 2017-01-14
Serendipity HIGH 8.8
CVE-2017-5476

Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.

Fix: after 2.0.5
Fix from $1,950 2017-01-14
Serendipity MEDIUM 6.1
CVE-2017-5474

Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct …

Fix: after 2.0.5
Fix from $1,600 2017-01-14
Serendipity CRITICAL 9.8
CVE-2016-10082

include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-…

Fix: after 2.0.5
Fix from $2,300 2016-12-30
Serendipity MEDIUM 5.4
CVE-2016-9681

Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HT…

Fix: after 2.0.4
Fix from $1,600 2016-12-25
Serendipity HIGH 8.6
CVE-2016-9752

In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) H…

Fix: after 2.0.4
Fix from $1,950 2016-12-01
Serendipity MEDIUM 5.4
CVE-2015-8603

Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipi…

Fix: after 2.0.2
Fix from $1,600 2016-01-12
Serendipity MEDIUM 6.5
CVE-2015-6968

Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.…

Fix: after 2.0.1
Fix from $1,600 2015-09-16
Serendipity MEDIUM 6.0
CVE-2015-6943

SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when "Us…

Fix: after 2.0.1
Fix from $1,600 2015-09-15
Serendipity HIGH 7.5
CVE-2012-2332

SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL command…

Fix: after 1.6
Fix from $1,950 2012-08-13
Serendipity HIGH 7.5
CVE-2012-2762

SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands vi…

Fix: after 1.6.1
Fix from $1,950 2012-06-07