CVE-2007-6390
mycalendar <0.13 - CSRF
Title source: llmDescription
Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page.
Scores
EPSS
0.0014
EPSS Percentile
33.9%
Classification
CWE
CWE-352
Status
draft
Affected Products (1)
serendipity/serendipity
< 0.12
Timeline
Published
Dec 17, 2007
Tracked Since
Feb 18, 2026