CVE-2023-53933
- EPSS 0.59%
- Veröffentlicht 17.12.2025 22:44:59
- Zuletzt bearbeitet 24.12.2025 16:52:17
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute ...
CVE-2023-53932
- EPSS 0.04%
- Veröffentlicht 17.12.2025 22:44:59
- Zuletzt bearbeitet 27.12.2025 17:15:44
Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users vi...
CVE-2024-58282
- EPSS 0.45%
- Veröffentlicht 10.12.2025 21:14:19
- Zuletzt bearbeitet 19.12.2025 17:46:31
Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell wi...
CVE-2023-31576
- EPSS 0.15%
- Veröffentlicht 16.05.2023 14:15:09
- Zuletzt bearbeitet 23.01.2025 17:15:10
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
CVE-2020-10964
- EPSS 3.8%
- Veröffentlicht 25.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:27
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.
CVE-2011-4090
- EPSS 1.43%
- Veröffentlicht 26.11.2019 05:15:12
- Zuletzt bearbeitet 21.11.2024 01:31:49
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
CVE-2011-1135
- EPSS 0.86%
- Veröffentlicht 05.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:25:37
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.
CVE-2011-1134
- EPSS 5%
- Veröffentlicht 05.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:25:37
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
CVE-2011-1133
- EPSS 0.86%
- Veröffentlicht 05.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:25:37
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.
CVE-2016-10752
- EPSS 0.75%
- Veröffentlicht 24.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:39
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.