VendorsS9Yserendipity2.0.3
Vulnerabilities

S9Y Serendipity 2.0.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2016-10752
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.
Published 2019-05-24 · Modified
9.8EPSS 0.023
CVE-2017-1000129
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
Published 2017-11-17 · Modified
7.5EPSS 0.011