Product
high
advisory
SSRF Vulnerability in Serendipity serendipity_url_allowed
1 TTP 1 CVESerendipity versions prior to 2.6.0 contain a Server-Side Request Forgery vulnerability allowing authenticated admins to reach internal network resources using bypassed address filters.
Serendipity
1t
1c
high
advisory
Authentication Context Confusion in Serendipity
1 TTP 1 CVESerendipity versions prior to 2.6.1 are vulnerable to an authentication context confusion flaw allowing an authenticated Editor to escalate privileges to Administrator via username collision.
Serendipity
1t
1c