CVE-2023-53932

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:s9y:serendipity:2.4.0:-:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-17 23:15

Updated : 2025-12-27 17:15


NVD link : CVE-2023-53932

Mitre link : CVE-2023-53932

CVE.ORG link : CVE-2023-53932


JSON object : View

Products Affected

s9y

  • serendipity
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')