Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Serendipity HIGH 8.8
CVE-2023-53933

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extensi…

No fix yet
Fix from $1,950 2025-12-17
Serendipity MEDIUM 5.4
CVE-2023-53932

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry…

No fix yet
Fix from $1,600 2025-12-17
Serendipity HIGH 7.2
CVE-2024-58282

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the m…

No fix yet
Fix from $1,950 2025-12-10
Serendipity HIGH 8.8
CVE-2023-31576

An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.

No fix yet
Fix from $1,950 2023-05-16
Serendipity CRITICAL 9.8
CVE-2016-10752

serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi…

Mitigation only
Fix from $2,300 2019-05-24
Serendipity MEDIUM 5.4
CVE-2016-10737

Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.

No fix yet
Fix from $1,600 2019-01-16
Serendipity HIGH 7.5
CVE-2017-1000129

Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure

Mitigation only
Fix from $1,950 2017-11-17
Serendipity MEDIUM 5.4
CVE-2017-8102

Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. Th…

No fix yet
Fix from $1,600 2017-04-24
Serendipity MEDIUM 5.0
CVE-2011-3800

Serendipity 1.5.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

Mitigation only
Fix from $1,600 2011-09-24
Serendipity MEDIUM 6.8
CVE-2006-6242

Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .…

No fix yet
Fix from $1,600 2006-12-03
Serendipity HIGH 7.5
CVE-2006-1910

config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and lat…

No fix yet
Fix from $1,950 2006-04-20