CVE-2016-10737: s9y Serendipity

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.

Affected products

  • s9y Serendipity: version 2.0.4 only

Published 2019-01-16. Last modified 2026-06-17.