Description Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. Remediation References CVE-2016-10737 Related Vulnerabilities WordPress Plugin WP Publication Archive 'file' Parameter Directory Traversal (2.3) Internet Information Services CVE-2009-4444 Vulnerability (CVE-2009-4444) Cherokee Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-20798) WordPress Plugin Mang Board WP Unspecified Vulnerability (2.0.3) WordPress Plugin Slimstat Analytics Cross-Site Scripting (4.1.5.2) Severity Medium Classification CVE-2016-10737 CWE-707 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities