s9y kayıtları
s9y üreticisine ait 61 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %6,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-434 Unrestricted Upload of File with Dangerous Type6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-284 Improper Access Control1
- CWE-565 Reliance on Cookies without Validation and Integrity Checking1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
61 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2011-1134İstismar yok | Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code s9y · serendipity · CWE-434 | Kritik9,8 | — | %3,0 | 5 Kas 2019 |
40Planlayın | CVE-2016-10082İstismar yok | include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack durings9y · serendipity · CWE-284 | Kritik9,8 | — | %2,9 | 30 Ara 2016 |
40Planlayın | CVE-2020-10964İstismar yok | Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a s9y · serendipity · CWE-434 | Kritik9,8 | — | %2,8 | 25 Mar 2020 |
40Planlayın | CVE-2016-10752İstismar yok | serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles as9y · serendipity · CWE-434 | Kritik9,8 | — | %2,3 | 24 May 2019 |
40Planlayın | CVE-2005-1449İstismar yok | Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.s9y · serendipity | Kritik10,0 | — | %1,4 | 3 May 2005 |
40Planlayın | CVE-2005-1452İstismar yok | Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."s9y · serendipity | Kritik10,0 | — | %1,4 | 3 May 2005 |
35İzleyin | CVE-2017-5609İstismar yok | SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrarys9y · serendipity · CWE-89 | Yüksek8,8 | — | %1,6 | 28 Oca 2017 |
35İzleyin | CVE-2023-31576İstismar yok | An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript s9y · serendipity · CWE-434 | Yüksek8,8 | — | %1,1 | 16 May 2023 |
35İzleyin | CVE-2017-5476İstismar yok | Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.s9y · serendipity · CWE-352 | Yüksek8,8 | — | %0,7 | 14 Oca 2017 |
35İzleyin | CVE-2017-8101İstismar yok | There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.s9y · serendipity · CWE-352 | Yüksek8,8 | — | %0,6 | 24 Nis 2017 |
35İzleyin | CVE-2017-5475İstismar yok | comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.s9y · serendipity · CWE-352 | Yüksek8,8 | — | %0,6 | 14 Oca 2017 |
34İzleyin | CVE-2016-9752İstismar yok | In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirs9y · serendipity · CWE-918 | Yüksek8,6 | — | %1,1 | 1 Ara 2016 |
34İzleyin | CVE-2024-58282İstismar yok | Serendipity 2.5.0 Remote Code Execution via Authenticated Media Uploads9y · serendipity · CWE-434 | Yüksek8,6 | — | %1,0 | 10 Ara 2025 |
34İzleyin | CVE-2023-53933İstismar yok | Serendipity 2.4.0 Authenticated Remote Code Execution via File Uploads9y · serendipity · CWE-434 | Yüksek8,7 | — | %1,0 | 17 Ara 2025 |
31İzleyin | CVE-2004-2158Kavram kanıtı | SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter tos9y · serendipity | Yüksek7,5 | — | %4,1 | 31 Ara 2004 |
31İzleyin | CVE-2010-1916İstismar yok | The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote axinha · wysiwyg editor · CWE-264 | Yüksek7,5 | — | %3,3 | 12 May 2010 |
31İzleyin | CVE-2012-2762İstismar yok | SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL cos9y · serendipity · CWE-89 | Yüksek7,5 | — | %2,2 | 7 Haz 2012 |
31İzleyin | CVE-2005-1134Kavram kanıtı | SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1s9y · serendipity | Yüksek7,5 | — | %1,8 | 13 Nis 2005 |
30İzleyin | CVE-2012-2332Kavram kanıtı | SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQs9y · serendipity · CWE-89 | Yüksek7,5 | — | %1,7 | 13 Ağu 2012 |
30İzleyin | CVE-2005-1451İstismar yok | The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.s9y · serendipity | Yüksek7,5 | — | %1,6 | 3 May 2005 |
30İzleyin | CVE-2006-2495İstismar yok | Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unaus9y · serendipity | Yüksek7,5 | — | %1,5 | 19 May 2006 |
30İzleyin | CVE-2006-1910İstismar yok | config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.phs9y · serendipity | Yüksek7,5 | — | %1,5 | 20 Nis 2006 |
30İzleyin | CVE-2009-3337İstismar yok | SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to es9y · serendipity event freetag · CWE-89 | Yüksek7,5 | — | %1,4 | 24 Eyl 2009 |
30İzleyin | CVE-2005-1450İstismar yok | Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.s9y · serendipity | Yüksek7,5 | — | %1,3 | 3 May 2005 |
30İzleyin | CVE-2017-1000129İstismar yok | Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosures9y · serendipity · CWE-89 | Yüksek7,5 | — | %1,1 | 17 Kas 2017 |
- CVE-2011-113440Planlayın
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code
KritikCVSS 9,8İstismar yokEPSS %3s9y · serendipity5 Kas 2019
- CVE-2016-1008240Planlayın
include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during
KritikCVSS 9,8İstismar yokEPSS %3s9y · serendipity30 Ara 2016
- CVE-2020-1096440Planlayın
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a
KritikCVSS 9,8İstismar yokEPSS %3s9y · serendipity25 Mar 2020
- CVE-2016-1075240Planlayın
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles a
KritikCVSS 9,8İstismar yokEPSS %2s9y · serendipity24 May 2019
- CVE-2005-144940Planlayın
Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.
KritikCVSS 10,0İstismar yokEPSS %1s9y · serendipity3 May 2005
- CVE-2005-145240Planlayın
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."
KritikCVSS 10,0İstismar yokEPSS %1s9y · serendipity3 May 2005
- CVE-2017-560935İzleyin
SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary
YüksekCVSS 8,8İstismar yokEPSS %2s9y · serendipity28 Oca 2017
- CVE-2023-3157635İzleyin
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript
YüksekCVSS 8,8İstismar yokEPSS %1s9y · serendipity16 May 2023
- CVE-2017-547635İzleyin
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
YüksekCVSS 8,8İstismar yokEPSS %1s9y · serendipity14 Oca 2017
- CVE-2017-810135İzleyin
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.
YüksekCVSS 8,8İstismar yokEPSS %1s9y · serendipity24 Nis 2017
- CVE-2017-547535İzleyin
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
YüksekCVSS 8,8İstismar yokEPSS %1s9y · serendipity14 Oca 2017
- CVE-2016-975234İzleyin
In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redir
YüksekCVSS 8,6İstismar yokEPSS %1s9y · serendipity1 Ara 2016
- CVE-2024-5828234İzleyin
Serendipity 2.5.0 Remote Code Execution via Authenticated Media Upload
YüksekCVSS 8,6İstismar yokEPSS %1s9y · serendipity10 Ara 2025
- CVE-2023-5393334İzleyin
Serendipity 2.4.0 Authenticated Remote Code Execution via File Upload
YüksekCVSS 8,7İstismar yokEPSS %1s9y · serendipity17 Ara 2025
- CVE-2004-215831İzleyin
SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to
YüksekCVSS 7,5Kavram kanıtıEPSS %4s9y · serendipity31 Ara 2004
- CVE-2010-191631İzleyin
The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote a
YüksekCVSS 7,5İstismar yokEPSS %3xinha · wysiwyg editor12 May 2010
- CVE-2012-276231İzleyin
SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL co
YüksekCVSS 7,5İstismar yokEPSS %2s9y · serendipity7 Haz 2012
- CVE-2005-113431İzleyin
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1
YüksekCVSS 7,5Kavram kanıtıEPSS %2s9y · serendipity13 Nis 2005
- CVE-2012-233230İzleyin
SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %2s9y · serendipity13 Ağu 2012
- CVE-2005-145130İzleyin
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.
YüksekCVSS 7,5İstismar yokEPSS %2s9y · serendipity3 May 2005
- CVE-2006-249530İzleyin
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unau
YüksekCVSS 7,5İstismar yokEPSS %2s9y · serendipity19 May 2006
- CVE-2006-191030İzleyin
config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.ph
YüksekCVSS 7,5İstismar yokEPSS %1s9y · serendipity20 Nis 2006
- CVE-2009-333730İzleyin
SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to e
YüksekCVSS 7,5İstismar yokEPSS %1s9y · serendipity event freetag24 Eyl 2009
- CVE-2005-145030İzleyin
Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.
YüksekCVSS 7,5İstismar yokEPSS %1s9y · serendipity3 May 2005
- CVE-2017-100012930İzleyin
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
YüksekCVSS 7,5İstismar yokEPSS %1s9y · serendipity17 Kas 2017