Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1. | |
| Title | Serendipity 2.3.5 Reflected XSS via search clean-URL route | |
| First Time appeared |
S9y
S9y serendipity |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:s9y:serendipity:2.3.5:*:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.4.0:-:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.4.0:beta1:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.5.0:-:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.6.0:-:*:*:*:*:*:* cpe:2.3:a:s9y:serendipity:2.6.0:beta1:*:*:*:*:*:* |
|
| Vendors & Products |
S9y
S9y serendipity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T11:28:26.954Z
Reserved: 2026-08-13T11:17:25.160Z
Link: CVE-2026-73628
No data.
Status : Received
Published: 2026-08-13T12:17:28.183
Modified: 2026-08-13T12:17:28.183
Link: CVE-2026-73628
No data.
OpenCVE Enrichment
No data.
Weaknesses