Serendipity 2.6.0 contains multiple security vulnerabilities: a critical bug in username logic allowing duplication of existing usernames and capture of account rights; a cross-site scripting (XSS) injection vector on the search page where search terms were not properly escaped; an outdated blacklist for downloads in the media library exposing blocked network resources; and an open redirect vulnerability in exit.php when the trackexit plugin is installed and URL redirects are configured.
| Vendor | Product | Versions |
|---|---|---|
| serendipity project | serendipity | 2.6.0 |