Vulnerabilities > Serenity > Serenity
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-19 | CVE-2024-26318 | Cross-site Scripting vulnerability in Serenity Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character. | 6.1 |