Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

S9y

First CVE: Oct 21, 2004Active for: 22 yearsTotal CVEs: 61
42.9
VTI Score
High

S9y maintains the Serendipity blogging platform and related components, a modestly represented but prominent presence in the web publishing landscape with an exposure that concentrates in a narrow product line. Vulnerabilities affecting the vendor span a cluster of web-application weakness classes—cross-site scripting, SQL injection, unrestricted file uploads, and cross-site request forgery—that are characteristic of server-side content-management and user-input handling, and a meaningful share of disclosures reach serious severity. The platform's recurring weaknesses reflect both the parsing and database-interaction demands inherent to a blogging engine and the complexity of securing dynamically generated content, particularly where user plugins and theme customization are involved. Public exploit code and proof-of-concept demonstrations have frequently accompanied this vendor's disclosures, making proof-of-concept availability a notable trend for defenders tracking patches. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
61
Total CVEs
More Total CVEs than 99% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by S9y over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2004
21 years ago
Most Recent CVE
Apr 15, 2026
101 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-10082CRITICAL
include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fa
Dec 30, 20169.833NONO
CVE-2011-4090MEDIUM
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
Nov 26, 20196.132NOYES
CVE-2016-10752CRITICAL
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename
May 24, 20199.831NONO
CVE-2012-2332HIGH
SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[plugin_to
Aug 13, 20127.531NOYES
CVE-2011-1134CRITICAL
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
Nov 5, 20199.830NONO
CVE-2020-10964CRITICAL
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to ha
Mar 25, 20209.829NONO
CVE-2004-2158HIGH
SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.
Dec 31, 20047.529NOYES
CVE-2023-53933HIGH
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files
Dec 17, 20258.828NONO
CVE-2023-31576HIGH
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
May 16, 20238.828NONO
CVE-2017-5609HIGH
SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.
Jan 28, 20178.828NONO
View all 61 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products61 CVEs
54%
36%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (42.6%)
Unknown35 (57.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (41.0%)
High1 (1.6%)
Unknown35 (57.4%)
User Interaction
None11 (18.0%)
Unknown35 (57.4%)
Required15 (24.6%)
Privileges Required
Low8 (13.1%)
High1 (1.6%)
None17 (27.9%)
Unknown35 (57.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (61 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
16.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by S9y.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by S9y — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For S9y's Products

View all 4 CNAs →

Top CWEs