Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4504 articles · 179618 vulns · 37/41 feeds (7d)
← Back to list
EST
PRE-CVEPATCHED
serendipity project · serendipity

Serendipity 2.6.0 Multiple Security Vulnerabilities Including Username Takeover and XSS

56% confidence

Description

Serendipity 2.6.0 contains multiple security vulnerabilities: a critical bug in username logic allowing duplication of existing usernames and capture of account rights; a cross-site scripting (XSS) injection vector on the search page where search terms were not properly escaped; an outdated blacklist for downloads in the media library exposing blocked network resources; and an open redirect vulnerability in exit.php when the trackexit plugin is installed and URL redirects are configured.

Affected Products

VendorProductVersions
serendipity projectserendipity2.6.0

Related News (1 articles)

Tier C
oss-security3h ago
Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.6.1
CWECWE-639, CWE-79, CWE-601
PublishedJul 23, 2026
Last enriched2h ago
Tags
authenticationinjectionopen-redirectphpblogopen-source
Trending Score30
Source articles1
Independent1
Info Completeness8/14
Missing: cve_id, cvss, epss, kev, exploit, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 56%

Vulnerability Timeline

CVE Published
Jul 23, 2026
Discovered by ZDM
Jul 23, 2026
Patch Available
Jul 23, 2026