Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-1000129 |
|
SQL Injection in sqli (CVE-2017-1000129)
SQL injection in sqli (CVE-2017-1000129). Confidential information can be exposed externally.
|
| CVE-2017-8101 |
|
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.
|
| CVE-2017-8102 |
|
Cross-Site Scripting (XSS) in s9y (CVE-2017-8102)
cross-site scripting in s9y (CVE-2017-8102). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5609 |
|
SQL Injection in sqli (CVE-2017-5609)
SQL injection in sqli (CVE-2017-5609). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5474 |
|
Open Redirect in s9y (CVE-2017-5474)
vulnerability in s9y (CVE-2017-5474). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2017-5475 |
|
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
|
| CVE-2017-5476 |
|
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
|