S9y

Serendipity

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 13.08.2026 11:28:27
  • Zuletzt bearbeitet 14.08.2026 19:18:00

Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. Authenticated users with adminImagesAdd permis...

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 11:28:26
  • Zuletzt bearbeitet 13.08.2026 16:19:07

Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTM...

  • EPSS 0.21%
  • Veröffentlicht 31.07.2026 14:19:01
  • Zuletzt bearbeitet 01.08.2026 00:17:17

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is conf...

  • EPSS 0.37%
  • Veröffentlicht 30.07.2026 13:57:51
  • Zuletzt bearbeitet 31.07.2026 23:17:26

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a username coll...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 14.04.2026 23:35:49
  • Zuletzt bearbeitet 23.04.2026 13:59:19

Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_SERVER['HTTP_HOST'] directly into the Message-ID SMTP header without validation, and the existing sani...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 14.04.2026 23:31:13
  • Zuletzt bearbeitet 23.04.2026 13:58:30

Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] without validation as the domain parameter of setcookie(). An attacker w...

Exploit
  • EPSS 0.99%
  • Veröffentlicht 17.12.2025 22:44:59
  • Zuletzt bearbeitet 24.12.2025 16:52:17

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute ...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 17.12.2025 22:44:59
  • Zuletzt bearbeitet 27.12.2025 17:15:44

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users vi...

Exploit
  • EPSS 1%
  • Veröffentlicht 10.12.2025 21:14:19
  • Zuletzt bearbeitet 19.12.2025 17:46:31

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell wi...

Exploit
  • EPSS 1.06%
  • Veröffentlicht 16.05.2023 14:15:09
  • Zuletzt bearbeitet 23.01.2025 17:15:10

An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.