AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T15:18:01.103Z and has not been modified since then. The vulnerability exists in the exit.php file of Serendipity when the Track Exits plugin is configured with comment redirection set to s9y. This open redirect vulnerability allows unauthenticated attackers to redirect users to arbitrary external [truncated]
Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. This HIGH severity vulnerability has a CVSS score of 8.7. Users of Serendipity versions before 2.6.1, particularly those with Editor and Administrator accounts, should review and apply patches to prevent pote [truncated]
CVE-2017-5609 is a high-severity SQL injection issue in Serendipity 2.0.5. According to the official NVD record, a remote authenticated user can trigger arbitrary SQL commands through the cat parameter in include/functions_entries.inc.php. NVD rates the issue CVSS 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), reflecting high impact with relatively low attack complexity.
CVE-2017-5476 affects Serendipity through version 2.0.5. The issue is a cross-site request forgery (CSRF) weakness that can be used to trigger installation of an event plugin or sidebar plugin. Because the action can be induced remotely through a crafted web request and relies on a victim’s authenticated session, it is most relevant to administrators and users with plugin-management access.
CVE-2017-5475 is a cross-site request forgery issue in Serendipity's comment.php. According to NVD, affected versions extend through 2.0.5, and the weakness is classified as CWE-352. The published NVD vector is CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, which NVD rates as 8.8 HIGH. The issue is referenced by a SecurityFocus BID entry and a Serendipity GitHub issue tracker report.
CVE-2017-5474 is an open redirect vulnerability in Serendipity through 2.0.5, located in comment.php. An attacker can supply a URL in the HTTP Referer header and cause users to be redirected to an arbitrary website, which can be used for phishing. The issue was publicly disclosed on 2017-01-14 and is rated medium severity (CVSS 6.1).