Serendipity
68 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Serendipity, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Serendipity CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 3 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 68 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High23
- Medium37
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Serendipity.
- CVE-2026-73629Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses8.5
- CVE-2026-73628Serendipity 2.3.5 Reflected XSS via search clean-URL route6.1
- CVE-2026-67350Serendipity < 2.6.1 Open Redirect via exit.php4.3
- CVE-2026-67351Serendipity < 2.6.1 Authentication Bypass via Username Collision8.8
- CVE-2026-39971Serendipity: Host Header Injection leads to SMTP header injection via unvalidated HTTP_HOST7.2
- CVE-2026-39963Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain6.9
- CVE-2023-53933Serendipity 2.4.0 Authenticated Remote Code Execution via File Upload8.8
- CVE-2023-53932Serendipity 2.4.0 Stored Cross-Site Scripting via Admin Entry Creation5.4
- CVE-2024-58282Serendipity 2.5.0 Remote Code Execution via Authenticated Media Upload7.2
- CVE-2023-31576An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.8.8
- CVE-2020-10964Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.9.8
- CVE-2011-4090Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.6.1
- CVE-2011-1135Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/Im...6.1
- CVE-2011-1134Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.9.8
- CVE-2011-1133Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.6.1
Product grouping is registry-driven, with AI assist and human review. How it works