Vulnerabilities > S9Y > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-22 CVE-2011-3610 Cross-site Scripting vulnerability in S9Y Serendipity Event Freetag
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.
network
low complexity
s9y CWE-79
6.1
2019-11-26 CVE-2011-4090 Cross-site Scripting vulnerability in S9Y Serendipity
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
network
low complexity
s9y CWE-79
6.1
2019-11-05 CVE-2011-1135 Cross-site Scripting vulnerability in S9Y Serendipity
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.
network
low complexity
s9y CWE-79
6.1
2019-11-05 CVE-2011-1133 Cross-site Scripting vulnerability in S9Y Serendipity
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.
network
low complexity
s9y CWE-79
6.1
2019-05-09 CVE-2019-11870 Cross-site Scripting vulnerability in S9Y Serendipity
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
network
low complexity
s9y CWE-79
6.1
2019-01-16 CVE-2016-10737 Cross-site Scripting vulnerability in S9Y Serendipity 2.0.4
Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.
network
low complexity
s9y CWE-79
5.4
2017-04-24 CVE-2017-8102 Cross-site Scripting vulnerability in S9Y Serendipity 2.1
Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user.
network
low complexity
s9y CWE-79
5.4
2017-01-14 CVE-2017-5474 Open Redirect vulnerability in S9Y Serendipity
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
network
low complexity
s9y CWE-601
6.1
2016-12-25 CVE-2016-9681 Cross-site Scripting vulnerability in S9Y Serendipity
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.
network
low complexity
s9y CWE-79
5.4
2016-01-12 CVE-2015-8603 Cross-site Scripting vulnerability in S9Y Serendipity
Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipity[entry_id] parameter in an "edit" admin action to serendipity_admin.php.
network
low complexity
s9y CWE-79
5.4