Lucene search

K

Serendipity Security Vulnerabilities

cve
cve

CVE-2017-1000129

Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure

7.5CVSS

7.5AI Score

0.001EPSS

2022-10-03 04:23 PM
24
cve
cve

CVE-2017-5474

Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.

6.1CVSS

6.7AI Score

0.001EPSS

2017-01-14 07:59 AM
24
cve
cve

CVE-2017-5475

comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.

8.8CVSS

8.7AI Score

0.001EPSS

2017-01-14 07:59 AM
27
cve
cve

CVE-2017-5476

Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.

8.8CVSS

8.7AI Score

0.001EPSS

2017-01-14 07:59 AM
29
cve
cve

CVE-2017-5609

SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.

8.8CVSS

8.8AI Score

0.001EPSS

2017-01-28 06:59 PM
21
cve
cve

CVE-2017-8101

There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.

8.8CVSS

8.5AI Score

0.001EPSS

2022-10-03 04:23 PM
27
cve
cve

CVE-2017-8102

Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a set_config error in that plugin.

5.4CVSS

5.1AI Score

0.001EPSS

2022-10-03 04:23 PM
26
cve
cve

CVE-2019-11870

Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.

6.1CVSS

5.8AI Score

0.001EPSS

2019-05-09 11:29 PM
30
cve
cve

CVE-2020-10964

Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.

9.8CVSS

9.7AI Score

0.028EPSS

2020-03-25 10:15 PM
61
cve
cve

CVE-2023-31576

An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.

8.8CVSS

8.7AI Score

0.001EPSS

2023-05-16 02:15 PM
97
Total number of security vulnerabilities60