CVE-2026-67350 LOW

CVE-2026-67350: Serendipity < 2.6.1 Open Redirect via exit.php

Vendor S9Y
Product Serendipity
Weakness CWE-601 · Open redirect
Published July 31, 2026
Last update July 31, 2026

CVSS base score

2.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.

Key dates

02Disclosure timeline

July 31, 2026 CVE published
July 31, 2026 Record updated

Related vulnerabilities

04Related CVE