Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Serendipity MEDIUM 5.0
CVE-2011-3800

Serendipity 1.5.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

Mitigation only
Fix from $1,600 2011-09-24
Serendipity MEDIUM 6.0
CVE-2009-4412

Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary code by uploading a file with…

Fix: after 1.5
Fix from $1,600 2009-12-24
Serendipity Event Freetag HIGH 7.5
CVE-2009-3337

SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to execute ar…

Fix: 3.09+
Fix from $1,950 2009-09-24
Serendipity MEDIUM 6.8
CVE-2006-6242

Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .…

No fix yet
Fix from $1,600 2006-12-03
Serendipity HIGH 7.5
CVE-2006-2495

Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized …

Patch available
Fix from $1,950 2006-05-20
Serendipity HIGH 7.5
CVE-2006-1910

config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and lat…

No fix yet
Fix from $1,950 2006-04-20
Serendipity MEDIUM 5.1
CVE-2005-3129EPSS 5%

Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged …

Fix: after 0.8.4
Fix from $1,600 2005-10-04
Serendipity HIGH 10.0
CVE-2005-1449

Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.

Patch available
Fix from $1,950 2005-05-03
Serendipity HIGH 10.0
CVE-2005-1452

Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."

Patch available
Fix from $1,950 2005-05-03
Serendipity HIGH 7.5
CVE-2005-1450

Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.

Patch available
Fix from $1,950 2005-05-03
Serendipity HIGH 7.5
CVE-2005-1451

The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.

Patch available
Fix from $1,950 2005-05-03
Serendipity MEDIUM 6.8
CVE-2005-1448

Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HT…

Patch available
Fix from $1,600 2005-05-03
Serendipity HIGH 7.5
CVE-2005-1134

SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id …

Patch available
Fix from $1,950 2005-04-13
Serendipity HIGH 7.5
CVE-2004-2158

SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit…

Patch available
Fix from $1,950 2004-12-31
Serendipity MEDIUM 5.0
CVE-2004-1620EPSS 8%

CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML …

Patch available
Fix from $1,600 2004-10-21