Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
s9y vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2005-1452
Serendipity prior to 0.8 allows Chief users to "hide plugins installed by other users."
S9y Serendipity 0.7
S9y Serendipity 0.7.1
S9y Serendipity 0.4
S9y Serendipity 0.6 Pl3
S9y Serendipity 0.3
S9y Serendipity 0.5 Pl1
5.8
CVSSv2
CVE-2017-5474
Open redirect vulnerability in comment.php in Serendipity up to and including 2.0.5 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
S9y Serendipity
6.8
CVSSv2
CVE-2017-5475
comment.php in Serendipity up to and including 2.0.5 allows CSRF in deleting any comments.
S9y Serendipity
4.3
CVSSv2
CVE-2011-4090
Serendipity prior to 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
S9y Serendipity
1 EDB exploit
3.5
CVSSv2
CVE-2015-2289
Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity prior to 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when creating a new category.
S9y Serendipity
7.5
CVSSv2
CVE-2020-10964
Serendipity prior to 2.3.4 on Windows allows remote malicious users to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.
S9y Serendipity
6.8
CVSSv2
CVE-2017-5476
Serendipity up to and including 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
S9y Serendipity
5.1
CVSSv2
CVE-2005-3129
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and previous versions allows remote malicious users to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.
S9y Serendipity
3.5
CVSSv2
CVE-2016-9681
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity prior to 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.
S9y Serendipity
5
CVSSv2
CVE-2016-9752
In Serendipity prior to 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status code.
S9y Serendipity
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »