Description Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. Remediation References CVE-2016-10737 Related Vulnerabilities phpMyAdmin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4345) phpMyFAQ Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2018-16651) PHP Integer Overflow or Wraparound Vulnerability (CVE-2017-5340) Atlassian Jira Other Vulnerability (CVE-2019-20101) Atlassian Jira Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-36234) Severity Medium Classification CVE-2016-10737 CWE-707 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities