CVE-2023-53932

MEDIUM

Serendipity 2.4.0 - XSS

Title source: llm

Description

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.

Exploits (1)

exploitdb WORKING POC
by Mirabbas Ağalarov · textwebappsphp
https://www.exploit-db.com/exploits/51373

Scores

CVSS v3 5.4
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
s9y/serendipity 2.4.0
s9y/Serendipity 2.4.0
Published Dec 17, 2025
Tracked Since Feb 18, 2026