CVE Tools

Serendipity

68 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Serendipity, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Serendipity CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Serendipity CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-123
2026-010
2026-020
2026-030
2026-042
2026-050
2026-060
2026-072
2026-082
2026-090

Severity

How the 68 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical69%
  • High2334%
  • Medium3754%
  • Low23%

Latest CVEs

The 15 most recently published vulnerabilities affecting Serendipity.

  1. CVE-2026-73629Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses8.5
  2. CVE-2026-73628Serendipity 2.3.5 Reflected XSS via search clean-URL route6.1
  3. CVE-2026-67350Serendipity < 2.6.1 Open Redirect via exit.php4.3
  4. CVE-2026-67351Serendipity < 2.6.1 Authentication Bypass via Username Collision8.8
  5. CVE-2026-39971Serendipity: Host Header Injection leads to SMTP header injection via unvalidated HTTP_HOST7.2
  6. CVE-2026-39963Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain6.9
  7. CVE-2023-53933Serendipity 2.4.0 Authenticated Remote Code Execution via File Upload8.8
  8. CVE-2023-53932Serendipity 2.4.0 Stored Cross-Site Scripting via Admin Entry Creation5.4
  9. CVE-2024-58282Serendipity 2.5.0 Remote Code Execution via Authenticated Media Upload7.2
  10. CVE-2023-31576An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.8.8
  11. CVE-2020-10964Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.9.8
  12. CVE-2011-4090Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.6.1
  13. CVE-2011-1135Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/Im...6.1
  14. CVE-2011-1134Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.9.8
  15. CVE-2011-1133Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store