CVSS
6.1
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 13, 2026
Exploitability
No EPSS data available
Serendipity versions >= 2.3.5 and ). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).