Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-39971
Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_S…
Serendipity
2.6.0+
MEDIUM 6.9
CVE-2026-39963
Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.ph…
Serendipity
2.6.0+
HIGH 8.8
CVE-2023-53933
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extensi…
Serendipity
No fix yet
MEDIUM 5.4
CVE-2023-53932
Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry…
Serendipity
No fix yet
HIGH 7.2
CVE-2024-58282
Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the m…
Serendipity
No fix yet
HIGH 8.8
CVE-2023-31576
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
Serendipity
No fix yet
CRITICAL 9.8
CVE-2020-10964
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This…
Serendipity
2.3.4+
MEDIUM 6.1
CVE-2011-3610
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_even…
Serendipity Event Freetag
3.30+
MEDIUM 6.1
CVE-2011-4090
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
Serendipity
1.6+
CRITICAL 9.8
CVE-2011-1134
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the im…
Serendipity
1.5.5+
MEDIUM 6.1
CVE-2011-1133
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugi…
Serendipity
1.5.5+
MEDIUM 6.1
CVE-2011-1135
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugin…
Serendipity
1.5.5+
CRITICAL 9.8
CVE-2016-10752
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensi…
Serendipity
Mitigation only
MEDIUM 6.1
CVE-2019-11870
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the template…
Serendipity
2.1.5+
MEDIUM 5.4
CVE-2016-10737
Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.
Serendipity
No fix yet
HIGH 7.5
CVE-2017-1000129
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
Serendipity
Mitigation only
HIGH 8.8
CVE-2017-8101
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.
Serendipity
Patch available
MEDIUM 5.4
CVE-2017-8102
Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. Th…
Serendipity
No fix yet
HIGH 8.8
CVE-2017-5609
SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL comm…
Serendipity
Patch available
HIGH 8.8
CVE-2017-5475
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
Serendipity
after 2.0.5
HIGH 8.8
CVE-2017-5476
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
Serendipity
after 2.0.5
MEDIUM 6.1
CVE-2017-5474
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct …
Serendipity
after 2.0.5
CRITICAL 9.8
CVE-2016-10082
include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-…
Serendipity
after 2.0.5
MEDIUM 5.4
CVE-2016-9681
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HT…
Serendipity
after 2.0.4
HIGH 8.6
CVE-2016-9752
In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) H…
Serendipity
after 2.0.4
MEDIUM 5.4
CVE-2015-8603
Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipi…
Serendipity
after 2.0.2
MEDIUM 6.5
CVE-2015-6968
Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.…
Serendipity
after 2.0.1
MEDIUM 6.0
CVE-2015-6943
SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when "Us…
Serendipity
after 2.0.1
HIGH 7.5
CVE-2012-2332
SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL command…
Serendipity
after 1.6
HIGH 7.5
CVE-2012-2762
SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands vi…
Serendipity
after 1.6.1