CVE-2024-58282
- EPSS 0.45%
- Veröffentlicht 10.12.2025 21:14:19
- Zuletzt bearbeitet 19.12.2025 17:46:31
Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell wi...
CVE-2008-1476
- EPSS 0.52%
- Veröffentlicht 24.03.2008 22:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to received trackbacks.
CVE-2007-6390
- EPSS 0.14%
- Veröffentlicht 17.12.2007 18:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to conduct cross-site scripting (XSS) attacks on the blog p...
- EPSS 0.43%
- Veröffentlicht 09.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipi...
CVE-2007-1326
- EPSS 0.48%
- Veröffentlicht 07.03.2007 21:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[multiCat][] parameter.
CVE-2006-5499
- EPSS 3.21%
- Veröffentlicht 25.10.2006 10:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity (s9y) 1.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the media manager administration page.