Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-53933 Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extensi… Serendipity No fix yet Fix from $1,9502025-12-17 MEDIUM 5.4 CVE-2023-53932 Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry… Serendipity No fix yet Fix from $1,6002025-12-17 HIGH 7.2 CVE-2024-58282 Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the m… Serendipity No fix yet Fix from $1,9502025-12-10 HIGH 8.8 CVE-2023-31576 An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. Serendipity No fix yet Fix from $1,9502023-05-16 CRITICAL 9.8 CVE-2016-10752 serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi… Serendipity Mitigation only Fix from $2,3002019-05-24 MEDIUM 5.4 CVE-2016-10737 Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. Serendipity No fix yet Fix from $1,6002019-01-16 HIGH 7.5 CVE-2017-1000129 Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure Serendipity Mitigation only Fix from $1,9502017-11-17 MEDIUM 5.4 CVE-2017-8102 Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. Th… Serendipity No fix yet Fix from $1,6002017-04-24 MEDIUM 5.0 CVE-2011-3800 Serendipity 1.5.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in… Serendipity Mitigation only Fix from $1,6002011-09-24 MEDIUM 6.8 CVE-2006-6242 Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .… Serendipity No fix yet Fix from $1,6002006-12-03 HIGH 7.5 CVE-2006-1910 config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and lat… Serendipity No fix yet Fix from $1,9502006-04-20