Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-39971 Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_S… Serendipity 2.6.0+ Fix from $1,9502026-04-15 MEDIUM 6.9 CVE-2026-39963 Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.ph… Serendipity 2.6.0+ Fix from $1,6002026-04-15 HIGH 8.8 CVE-2023-53933 Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extensi… Serendipity No fix yet Fix from $1,9502025-12-17 MEDIUM 5.4 CVE-2023-53932 Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry… Serendipity No fix yet Fix from $1,6002025-12-17 HIGH 7.2 CVE-2024-58282 Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the m… Serendipity No fix yet Fix from $1,9502025-12-10 HIGH 8.8 CVE-2023-31576 An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. Serendipity No fix yet Fix from $1,9502023-05-16 CRITICAL 9.8 CVE-2020-10964 Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This… Serendipity 2.3.4+ Fix from $2,3002020-03-25 MEDIUM 6.1 CVE-2011-3610 A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_even… Serendipity Event Freetag 3.30+ Fix from $1,6002020-01-22 MEDIUM 6.1 CVE-2011-4090 Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation. Serendipity 1.6+ Fix from $1,6002019-11-26 CRITICAL 9.8 CVE-2011-1134 Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the im… Serendipity 1.5.5+ Fix from $2,3002019-11-05 MEDIUM 6.1 CVE-2011-1133 Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugi… Serendipity 1.5.5+ Fix from $1,6002019-11-05 MEDIUM 6.1 CVE-2011-1135 Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugin… Serendipity 1.5.5+ Fix from $1,6002019-11-05 CRITICAL 9.8 CVE-2016-10752 serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi… Serendipity Mitigation only Fix from $2,3002019-05-24 MEDIUM 6.1 CVE-2019-11870 Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the template… Serendipity 2.1.5+ Fix from $1,6002019-05-09 MEDIUM 5.4 CVE-2016-10737 Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. Serendipity No fix yet Fix from $1,6002019-01-16 HIGH 7.5 CVE-2017-1000129 Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure Serendipity Mitigation only Fix from $1,9502017-11-17 HIGH 8.8 CVE-2017-8101 There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request. Serendipity Patch available Fix from $1,9502017-04-24 MEDIUM 5.4 CVE-2017-8102 Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. Th… Serendipity No fix yet Fix from $1,6002017-04-24 HIGH 8.8 CVE-2017-5609 SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL comm… Serendipity Patch available Fix from $1,9502017-01-28 HIGH 8.8 CVE-2017-5475 comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments. Serendipity after 2.0.5 Fix from $1,9502017-01-14 HIGH 8.8 CVE-2017-5476 Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin. Serendipity after 2.0.5 Fix from $1,9502017-01-14 MEDIUM 6.1 CVE-2017-5474 Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct … Serendipity after 2.0.5 Fix from $1,6002017-01-14 CRITICAL 9.8 CVE-2016-10082 include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-… Serendipity after 2.0.5 Fix from $2,3002016-12-30 MEDIUM 5.4 CVE-2016-9681 Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HT… Serendipity after 2.0.4 Fix from $1,6002016-12-25 HIGH 8.6 CVE-2016-9752 In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) H… Serendipity after 2.0.4 Fix from $1,9502016-12-01 MEDIUM 5.4 CVE-2015-8603 Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipi… Serendipity after 2.0.2 Fix from $1,6002016-01-12 MEDIUM 6.5 CVE-2015-6968 Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.… Serendipity after 2.0.1 Fix from $1,6002015-09-16 MEDIUM 6.0 CVE-2015-6943 SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when "Us… Serendipity after 2.0.1 Fix from $1,6002015-09-15 HIGH 7.5 CVE-2012-2332 SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL command… Serendipity after 1.6 Fix from $1,9502012-08-13 HIGH 7.5 CVE-2012-2762 SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands vi… Serendipity after 1.6.1 Fix from $1,9502012-06-07