{"apiVersion":"1.0","identifier":"CVE-2026-73628","description":"Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim-s browser. Fixed in 2.6.1.","publishedAt":"2026-08-13T12:17:28","lastModifiedAt":"2026-08-13T16:19:07","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73628","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","epssProbability":0.00155,"riskScore":0.62,"affectedProduct":"serendipity","affectedVersions":">=2.3.5,<=2.6.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73628","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73628","en":"https://www.redsauce.net/en/cves/CVE-2026-73628","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73628","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73628","de":"https://www.redsauce.net/de/cves/CVE-2026-73628","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73628","el":"https://www.redsauce.net/el/cves/CVE-2026-73628"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73628"}}