Back
CVE-2005-1448
Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Published: May 3, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (9)
| Vendor | Product | Version |
|---|---|---|
| s9y | serendipity | 0.7 |
| s9y | serendipity | 0.7.1 |
| s9y | serendipity | 0.7_beta1 |
| s9y | serendipity | 0.7_beta2 |
| s9y | serendipity | 0.7_beta3 |
| s9y | serendipity | 0.7_beta4 |
| s9y | serendipity | 0.7_rc1 |
| s9y | serendipity | 0.8_beta5 |
| s9y | serendipity | 0.8_beta6 |
GitHub Security Advisory GHSA-fjw5-crgv-6q7v
Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows...
References (8)
- http://secunia.com/advisories/15145 Patch, Vendor Advisory
- http://www.osvdb.org/15876 Patch
- http://www.s9y.org/63.html#A9 Patch
- http://www.securityfocus.com/bid/13411 Patch
- http://secunia.com/advisories/15145 Patch, Vendor Advisory
- http://www.osvdb.org/15876 Patch
- http://www.s9y.org/63.html#A9 Patch
- http://www.securityfocus.com/bid/13411 Patch
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
1.34%
Top 31% most likely to be exploited
Threat Score
27.6 / 100
Data Sources
NVD
EPSS
GitHub