Vulnerabilities
20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-39971 +1 in the same advisory: …39963 | Serendipity is a PHP-powered weblog engine. Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_SERVER['HTTP_HOST'] directly into the Message-ID SMTP header without validation, and the existing sanitization function serendipity_isResponseClean() is not called on HTTP_HOST before embedding it. An attacker who can control the Host header during an email-triggering action such as comment notifications or subscription emails can inject arbitrary SMTP headers into outgoing emails. This enables identity spoofing, reply hijacking via manipulated Message-ID threading, and email reputation abuse through the attacker's domain being embedded in legitimate mail headers. This issue has been fixed in version 2.6.0. NVD description · AI analysis pending | 7.2 group max | <1% | PoC |
| — | |
| CVE-2023-53933 +1 in the same advisory: …53932 | Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server. NVD description · AI analysis pending | 8.7 group max | 1% | PoC ×2 |
| — | |
| CVE-2024-58282 | Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrary system command execution on the web server. NVD description · AI analysis pending | 8.6 | 1% | PoC |
| — | |
| CVE-2023-31576 | An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2020-10964 | Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2016-10752 | serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless file serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2019-11870 | Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admi Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2016-10737 | Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2017-1000129 | Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2017-8101 +1 in the same advisory: …8102 | There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request. There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2017-5609 | SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via th SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2017-5476 | Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin. Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2016-10082 | include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time instal include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() call in the bundled-libs/serendipity_generateFTPChecksums.php file. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2016-9681 | Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a ca Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name. NVD description · AI analysis pending | 5.4 | 1% | PoC |
| — | |
| CVE-2016-9752 | In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status code. NVD description · AI analysis pending | 8.6 | 1% |
| — |