VDB
Sign up

package

Packagist/s9y/serendipity

pkg:packagist/s9y/serendipity

HIGH7.2Packagist
GHSA-458g-q4fh-mj6r· CVE-2026-39971

Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email header

Modified: 5/5/2026

MEDIUM6.9Packagist
GHSA-4m6c-649p-f6gf· CVE-2026-39963

Serendipity has a Host Header Injection allows authentication cookie scoping to attacker-controlled domain in functions_config.inc.php

Modified: 4/15/2026