Vulnerabilities
Vulnerable Software
S9y:  >> Serendipity  >> 2.4.0  Security Vulnerabilities
Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-12-17
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.
CVSS Score
8.8
EPSS Score
0.005
Published
2025-12-17
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-05-16


Contact Us

Shodan ® - All rights reserved