Description Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. Remediation References CVE-2016-10737 Related Vulnerabilities Moodle Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-7919) Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4937) Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4789) WordPress Plugin Wallable-Social Networking Arbitrary File Upload (1.1) WordPress Plugin Thrive Architect Security Bypass (2.6.7.3) Severity Medium Classification CVE-2016-10737 CWE-707 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities