Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1. | |
| Title | Serendipity 2.3.5 Reflected XSS via search clean-URL route | |
| First Time appeared |
S9y
S9y serendipity |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:s9y:serendipity:2.3.5:*:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.4.0:-:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.4.0:beta1:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.5.0:-:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.6.0:-:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.6.0:beta1:*:*:*:*:*:* |
|
| Vendors & Products |
S9y
S9y serendipity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T15:08:52.238Z
Reserved: 2026-08-13T11:17:25.160Z
Link: CVE-2026-73628
Updated: 2026-08-13T15:08:45.949Z
Status : Received
Published: 2026-08-13T12:17:28.183
Modified: 2026-08-13T16:19:07.240
Link: CVE-2026-73628
No data.
OpenCVE Enrichment
Updated: 2026-08-13T13:00:04Z