Description Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. Remediation References CVE-2016-10737 Related Vulnerabilities WordPress Plugin Metform Elementor Contact Form Builder-Flexible and Design-Friendly Contact Form builder for WordPress Security Bypass (3.3.0) TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-32768) MySQL Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2014-0001) WordPress Plugin WP ALL Export Pro Multiple Vulnerabilities (1.7.8) Mailman Other Vulnerability (CVE-2001-0884) Severity Medium Classification CVE-2016-10737 CWE-707 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities