Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Serendipity | S9y | 0.8 (including) | 0.8 (including) |