Serenity's vulnerability footprint is concentrated in a narrow set of web-facing products including Serene, StartSharp, and Serenity itself, with the durable signal centered on application-layer input-handling and credential-management issues such as cross-site scripting, sensitive information disclosure in error messages, and weak password-recovery mechanisms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Serenity over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31287HIGH An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This t | Apr 27, 2023 | 7.8 | 23 | NO | NO |
CVE-2023-31285MEDIUM An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to u | Apr 27, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-31286MEDIUM An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to re | Apr 27, 2023 | 5.3 | 18 | NO | NO |
CVE-2024-26318MEDIUM Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character. | Feb 19, 2024 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Serenity.
Media articles that mention a CVE ID that affects a product developed by Serenity — matched by CVE ID, not by vendor name.