{"id":"CVE-2026-73628","summary":"Serendipity 2.3.5 Reflected XSS via search clean-URL route","details":"Serendipity versions \u003e= 2.3.5 and \u003c= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/\u003cterm\u003e). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1.","aliases":["GHSA-6c2x-mjmq-vx4q"],"modified":"2026-10-02T03:30:29.484839781Z","published":"2026-08-13T11:28:26.954Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73628.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73628.json"},{"type":"ADVISORY","url":"https://github.com/s9y/Serendipity/security/advisories/GHSA-6c2x-mjmq-vx4q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73628"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/serendipity-reflected-xss-via-search-clean-url-route"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/s9y/serendipity","events":[{"introduced":"80676e4c9197758f5c793aa97aa86c1c088f988d"},{"last_affected":"87696c92730d75785d17b515125be3862cdfb49e"}],"database_specific":{"extracted_events":[{"introduced":"2.3.5"},{"last_affected":"2.6.0"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73628.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"}]}