S9y maintains the Serendipity blogging platform and related components, a modestly represented but prominent presence in the web publishing landscape with an exposure that concentrates in a narrow product line. Vulnerabilities affecting the vendor span a cluster of web-application weakness classes—cross-site scripting, SQL injection, unrestricted file uploads, and cross-site request forgery—that are characteristic of server-side content-management and user-input handling, and a meaningful share of disclosures reach serious severity. The platform's recurring weaknesses reflect both the parsing and database-interaction demands inherent to a blogging engine and the complexity of securing dynamically generated content, particularly where user plugins and theme customization are involved. Public exploit code and proof-of-concept demonstrations have frequently accompanied this vendor's disclosures, making proof-of-concept availability a notable trend for defenders tracking patches. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by S9y over time
Signals from CVEs in this vendor scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10082CRITICAL include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fa | Dec 30, 2016 | 9.8 | 33 | NO | NO |
CVE-2011-4090MEDIUM Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation. | Nov 26, 2019 | 6.1 | 32 | NO | YES |
CVE-2016-10752CRITICAL serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename | May 24, 2019 | 9.8 | 31 | NO | NO |
CVE-2012-2332HIGH SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[plugin_to | Aug 13, 2012 | 7.5 | 31 | NO | YES |
CVE-2011-1134CRITICAL Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager. | Nov 5, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-10964CRITICAL Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to ha | Mar 25, 2020 | 9.8 | 29 | NO | NO |
CVE-2004-2158HIGH SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php. | Dec 31, 2004 | 7.5 | 29 | NO | YES |
CVE-2023-53933HIGH Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files | Dec 17, 2025 | 8.8 | 28 | NO | NO |
CVE-2023-31576HIGH An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. | May 16, 2023 | 8.8 | 28 | NO | NO |
CVE-2017-5609HIGH SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter. | Jan 28, 2017 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (61 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by S9y.
Media articles that mention a CVE ID that affects a product developed by S9y — matched by CVE ID, not by vendor name.