Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Serendipity Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists in Serendipity version 2.5.0, allowing authenticated administrators to upload malicious PHP files via the media upload feature. Exploitation involves creating a PHP shell that can execute arbitrary system commands on the web server.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where Serendipity is hosted.

Reproduction

To reproduce this vulnerability, an authenticated administrator must upload a PHP file through the media upload feature. The uploaded file can be a PHP shell that includes a form for executing system commands. Once the file is uploaded, the shell can be accessed and used to execute commands on the server.

Added: Dec 10, 2025, 10:31 PM
Updated: Dec 10, 2025, 10:31 PM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
10.0
exploitability
6.7
remediation
0.0
relevance
1.4
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.