Serendipity
This hub aggregates every CVE we track for Serendipity, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
68
CVEs tracked
6
Critical
23
High
0
In CISA KEV
Severity distribution
MEDIUM37HIGH23CRITICAL6LOW2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
0
0
0
2
0
0
2
2
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Serendipity.
- CVE-2026-73629Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses8.5
- CVE-2026-73628Serendipity 2.3.5 Reflected XSS via search clean-URL route6.1
- CVE-2026-67350Serendipity < 2.6.1 Open Redirect via exit.php4.3
- CVE-2026-67351Serendipity < 2.6.1 Authentication Bypass via Username Collision8.8
- CVE-2026-39971Serendipity: Host Header Injection leads to SMTP header injection via unvalidated HTTP_HOST7.2
- CVE-2026-39963Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain6.9
- CVE-2023-53932Serendipity 2.4.0 Stored Cross-Site Scripting via Admin Entry Creation5.4
- CVE-2023-53933Serendipity 2.4.0 Authenticated Remote Code Execution via File Upload8.8
- CVE-2024-58282Serendipity 2.5.0 Remote Code Execution via Authenticated Media Upload7.2
- CVE-2023-31576An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.8.8
- CVE-2020-10964Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.9.8
- CVE-2011-4090Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.6.1
- CVE-2011-1135Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/Im...6.1
- CVE-2011-1134Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.9.8
- CVE-2011-1133Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.6.1
Product normalization is registry-driven with AI assist and human review. How it works