Skip to main content
Loading…
    CVE-2026-39963 — Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] without valida — CVE Database · The Intelligence Room