CVE-2007-6205

S9Y Serendipity <1.2.1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the remote RSS sidebar plugin (serendipity_plugin_remoterss) in S9Y Serendipity before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a link in an RSS feed.

Scores

EPSS 0.0090
EPSS Percentile 75.4%

Classification

CWE
CWE-79
Status draft

Affected Products (37)

s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
... and 22 more

Timeline

Published Dec 11, 2007
Tracked Since Feb 18, 2026