s9y CVE Vulnerabilities & Metrics

Focus on s9y vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About s9y Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with s9y. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total s9y CVEs: 25
Earliest CVE date: 21 Oct 2004, 04:00 UTC
Latest CVE date: 16 May 2023, 14:15 UTC

Latest CVE reference: CVE-2023-31576

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical s9y CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.58

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 33
7.0-8.9 14
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS s9y CVEs

These are the five CVEs with the highest CVSS scores for s9y, sorted by severity first and recency.

All CVEs for s9y

CVE-2023-31576 s9y vulnerability CVSS: 0 16 May 2023, 14:15 UTC

An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.

CVE-2020-10964 s9y vulnerability CVSS: 7.5 25 Mar 2020, 22:15 UTC

Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.

CVE-2011-3610 s9y vulnerability CVSS: 4.3 22 Jan 2020, 16:15 UTC

A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.

CVE-2011-4090 s9y vulnerability CVSS: 4.3 26 Nov 2019, 05:15 UTC

Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.

CVE-2011-1135 s9y vulnerability CVSS: 4.3 05 Nov 2019, 21:15 UTC

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.

CVE-2011-1134 s9y vulnerability CVSS: 7.5 05 Nov 2019, 21:15 UTC

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.

CVE-2011-1133 s9y vulnerability CVSS: 4.3 05 Nov 2019, 21:15 UTC

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.

CVE-2016-10752 s9y vulnerability CVSS: 7.5 24 May 2019, 18:29 UTC

serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.

CVE-2019-11870 s9y vulnerability CVSS: 4.3 09 May 2019, 23:29 UTC

Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.

CVE-2016-10737 s9y vulnerability CVSS: 3.5 16 Jan 2019, 04:29 UTC

Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.

CVE-2017-1000129 s9y vulnerability CVSS: 5.0 17 Nov 2017, 05:29 UTC

Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure

CVE-2017-8102 s9y vulnerability CVSS: 3.5 24 Apr 2017, 18:59 UTC

Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a set_config error in that plugin.

CVE-2017-8101 s9y vulnerability CVSS: 6.8 24 Apr 2017, 18:59 UTC

There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.

CVE-2017-5609 s9y vulnerability CVSS: 6.5 28 Jan 2017, 18:59 UTC

SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.

CVE-2017-5476 s9y vulnerability CVSS: 6.8 14 Jan 2017, 07:59 UTC

Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.

CVE-2017-5475 s9y vulnerability CVSS: 6.8 14 Jan 2017, 07:59 UTC

comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.

CVE-2017-5474 s9y vulnerability CVSS: 5.8 14 Jan 2017, 07:59 UTC

Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.

CVE-2016-10082 s9y vulnerability CVSS: 7.5 30 Dec 2016, 07:59 UTC

include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() call in the bundled-libs/serendipity_generateFTPChecksums.php file.

CVE-2016-9681 s9y vulnerability CVSS: 3.5 25 Dec 2016, 17:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.

CVE-2016-9752 s9y vulnerability CVSS: 5.0 01 Dec 2016, 11:59 UTC

In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status code.

CVE-2015-8603 s9y vulnerability CVSS: 3.5 12 Jan 2016, 19:59 UTC

Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipity[entry_id] parameter in an "edit" admin action to serendipity_admin.php.

CVE-2015-6969 s9y vulnerability CVSS: 4.3 16 Sep 2015, 14:59 UTC

Cross-site scripting (XSS) vulnerability in js/2k11.min.js in the 2k11 theme in Serendipity before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via a user name in a comment, which is not properly handled in a Reply link.

CVE-2015-6968 s9y vulnerability CVSS: 6.5 16 Sep 2015, 14:59 UTC

Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.2 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .pht or (2) .phtml extension.

CVE-2015-6943 s9y vulnerability CVSS: 6.0 15 Sep 2015, 18:59 UTC

SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when "Use Tokens for Comment Moderation" is enabled, allows remote administrators to execute arbitrary SQL commands via the serendipity[id] parameter to serendipity_admin.php.

CVE-2015-2289 s9y vulnerability CVSS: 3.5 23 Mar 2015, 16:59 UTC

Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when creating a new category.

CVE-2014-9432 s9y vulnerability CVSS: 4.3 31 Dec 2014, 22:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in templates/2k11/admin/overview.inc.tpl in Serendipity before 2.0-rc2 allow remote attackers to inject arbitrary web script or HTML via a blog comment in the QUERY_STRING to serendipity/index.php.

CVE-2013-5670 s9y vulnerability CVSS: 4.3 05 Nov 2013, 18:55 UTC

Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php in the htmlarea SpellChecker module, as used in Serendipity before 1.7.3 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the to_r_list parameter.

CVE-2013-5314 s9y vulnerability CVSS: 4.3 19 Aug 2013, 21:10 UTC

Cross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the serendipity[htmltarget] parameter.

CVE-2012-2332 s9y vulnerability CVSS: 7.5 13 Aug 2012, 23:55 UTC

SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[plugin_to_conf] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

CVE-2012-2331 s9y vulnerability CVSS: 4.3 13 Aug 2012, 23:55 UTC

Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

CVE-2012-2762 s9y vulnerability CVSS: 7.5 07 Jun 2012, 19:55 UTC

SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands via the url parameter to comment.php.

CVE-2011-3800 s9y vulnerability CVSS: 5.0 24 Sep 2011, 00:55 UTC

Serendipity 1.5.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/newspaper/layout.php and certain other files.

CVE-2010-2957 s9y vulnerability CVSS: 2.6 10 Sep 2010, 18:00 UTC

Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4, when "Remember me" logins are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-1916 s9y vulnerability CVSS: 7.5 12 May 2010, 11:46 UTC

The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.

CVE-2009-4412 s9y vulnerability CVSS: 6.0 24 Dec 2009, 16:30 UTC

Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in an unspecified directory. NOTE: some of these details are obtained from third party information.

CVE-2009-3337 s9y vulnerability CVSS: 7.5 24 Sep 2009, 16:30 UTC

SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to execute arbitrary SQL commands via an unspecified parameter associated with Meta keywords in a blog entry.

CVE-2008-1385 s9y vulnerability CVSS: 4.3 23 Apr 2008, 13:05 UTC

Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

CVE-2008-1386 s9y vulnerability CVSS: 4.3 23 Apr 2008, 13:05 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the installer in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary web script or HTML via (1) unspecified path fields or (2) the database host field. NOTE: the timing window for exploitation of this issue might be limited.

CVE-2008-0124 s9y vulnerability CVSS: 4.3 28 Feb 2008, 20:44 UTC

Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file.

CVE-2008-0751 s9y vulnerability CVSS: 4.3 13 Feb 2008, 20:00 UTC

Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/.

CVE-2007-6205 s9y vulnerability CVSS: 4.3 11 Dec 2007, 20:46 UTC

Cross-site scripting (XSS) vulnerability in the remote RSS sidebar plugin (serendipity_plugin_remoterss) in S9Y Serendipity before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a link in an RSS feed.

CVE-2006-6242 s9y vulnerability CVSS: 6.8 03 Dec 2006, 19:28 UTC

Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php; or to plugins/ scripts (2) serendipity_event_bbcode/serendipity_event_bbcode.php, (3) serendipity_event_browsercompatibility/serendipity_event_browsercompatibility.php, (4) serendipity_event_contentrewrite/serendipity_event_contentrewrite.php, (5) serendipity_event_creativecommons/serendipity_event_creativecommons.php, (6) serendipity_event_emoticate/serendipity_event_emoticate.php, (7) serendipity_event_entryproperties/serendipity_event_entryproperties.php, (8) serendipity_event_karma/serendipity_event_karma.php, (9) serendipity_event_livesearch/serendipity_event_livesearch.php, (10) serendipity_event_mailer/serendipity_event_mailer.php, (11) serendipity_event_nl2br/serendipity_event_nl2br.php, (12) serendipity_event_s9ymarkup/serendipity_event_s9ymarkup.php, (13) serendipity_event_searchhighlight/serendipity_event_searchhighlight.php, (14) serendipity_event_spamblock/serendipity_event_spamblock.php, (15) serendipity_event_spartacus/serendipity_event_spartacus.php, (16) serendipity_event_statistics/serendipity_plugin_statistics.php, (17) serendipity_event_templatechooser/serendipity_event_templatechooser.php, (18) serendipity_event_textile/serendipity_event_textile.php, (19) serendipity_event_textwiki/serendipity_event_textwiki.php, (20) serendipity_event_trackexits/serendipity_event_trackexits.php, (21) serendipity_event_weblogping/serendipity_event_weblogping.php, (22) serendipity_event_xhtmlcleanup/serendipity_event_xhtmlcleanup.php, (23) serendipity_plugin_comments/serendipity_plugin_comments.php, (24) serendipity_plugin_creativecommons/serendipity_plugin_creativecommons.php, (25) serendipity_plugin_entrylinks/serendipity_plugin_entrylinks.php, (26) serendipity_plugin_eventwrapper/serendipity_plugin_eventwrapper.php, (27) serendipity_plugin_history/serendipity_plugin_history.php, (28) serendipity_plugin_recententries/serendipity_plugin_recententries.php, (29) serendipity_plugin_remoterss/serendipity_plugin_remoterss.php, (30) serendipity_plugin_shoutbox/serendipity_plugin_shoutbox.php, and and (31) serendipity_plugin_templatedropdown/serendipity_plugin_templatedropdown.php.

CVE-2006-2495 s9y vulnerability CVSS: 7.5 20 May 2006, 03:02 UTC

Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.

CVE-2006-1910 s9y vulnerability CVSS: 7.5 20 Apr 2006, 18:06 UTC

config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2005-3129 s9y vulnerability CVSS: 5.1 04 Oct 2005, 22:02 UTC

Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.

CVE-2005-1713 s9y vulnerability CVSS: 4.3 24 May 2005, 04:00 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.

CVE-2005-1449 s9y vulnerability CVSS: 10.0 03 May 2005, 04:00 UTC

Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.

CVE-2005-1452 s9y vulnerability CVSS: 10.0 03 May 2005, 04:00 UTC

Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."

CVE-2005-1450 s9y vulnerability CVSS: 7.5 03 May 2005, 04:00 UTC

Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.

CVE-2005-1451 s9y vulnerability CVSS: 7.5 03 May 2005, 04:00 UTC

The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.

CVE-2005-1448 s9y vulnerability CVSS: 6.8 03 May 2005, 04:00 UTC

Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2005-1134 s9y vulnerability CVSS: 7.5 13 Apr 2005, 04:00 UTC

SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.

CVE-2004-2158 s9y vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.

CVE-2004-2157 s9y vulnerability CVSS: 4.3 31 Dec 2004, 05:00 UTC

Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field.

CVE-2004-2525 s9y vulnerability CVSS: 4.3 31 Dec 2004, 05:00 UTC

Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.

CVE-2004-1620 s9y vulnerability CVSS: 5.0 21 Oct 2004, 04:00 UTC

CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.