oM noM Security Feeds cve
vulnerability context

CVE-2016-10082

CVSS 9.8 CRITICALEPSS 85%CWE-284

include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() call in the bundled-libs/serendipity_generateFTPChecksums.php file.

Published 2016-12-30 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
9.8 / CRITICAL
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
85% percentile (score 0.0288)
CWE
CWE-284

source mentions 1

source consensus

  • Bluesky:@cyberhub.blog
Want the 3-bullet summary of CVE-2016-10082, plus webhook alerts when KEV is updated? Pro is $10/mo.