CVE-2010-2957

Serendipity <1.5.4 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4, when "Remember me" logins are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Scores

EPSS 0.0029
EPSS Percentile 51.6%

Classification

CWE
CWE-79
Status published

Affected Products (50)

s9y/serendipity < 1.5.3
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
... and 35 more

Timeline

Published Sep 10, 2010
Tracked Since Feb 18, 2026