VendorsS9Yserendipity2.6.0
Vulnerabilities

S9Y Serendipity 2.6.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-39971
Serendipity: Host Header Injection leads to SMTP header injection via unvalidated HTTP_HOST
Published 2026-04-14 · Analyzed
7.2EPSS 0.003
CVE-2026-39963
Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain
Published 2026-04-14 · Analyzed
6.9EPSS 0.003