Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
S9y
S9y serendipity |
|
| Vendors & Products |
S9y
S9y serendipity |
Wed, 17 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post. | |
| Title | Serendipity 2.4.0 Stored Cross-Site Scripting via Admin Entry Creation | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-17T22:44:59.094Z
Reserved: 2025-12-16T19:22:09.997Z
Link: CVE-2023-53932
No data.
Status : Received
Published: 2025-12-17T23:15:52.817
Modified: 2025-12-17T23:15:52.817
Link: CVE-2023-53932
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:56:10Z