Total vulnerabilities in the database
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: