Vulnerabilities > S9Y > Serendipity > 2.2.1

DATE CVE VULNERABILITY TITLE RISK
2020-03-25 CVE-2020-10964 Unrestricted Upload of File with Dangerous Type vulnerability in S9Y Serendipity
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot.
network
low complexity
s9y CWE-434
7.5
2020-01-22 CVE-2011-3610 Cross-site Scripting vulnerability in S9Y Serendipity Event Freetag
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.
network
s9y CWE-79
4.3