CVE-2023-53932: s9y Serendipity
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.
Affected products
- s9y Serendipity: version 2.4.0 only
Published 2025-12-17. Last modified 2026-06-17.