Vulnerabilities
24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-20053 | Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking auth Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the users endpoint with hidden fields containing admin credentials and account parameters to add new administrator accounts without user consent. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2026-21857 | REDAXO is a PHP-based content management system. REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backup addon does not validate the `EXPDIR` POST parameter against the UI-generated allowlist of permitted directories. An attacker can supply relative paths containing `../` sequences (or even absolute paths inside the document root) to include any readable file in the generated `.tar.gz` archive. Version 5.20.2 fixes this issue. NVD description · AI analysis pending | 8.3 | <1% | PoC |
| — | |
| CVE-2025-66026 | REDAXO is a PHP-based CMS. REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the Mediapool view where the request parameter args[types] is rendered into an info banner without HTML-escaping. This allows arbitrary JavaScript execution in the backend context when an authenticated user visits a crafted link while logged in. This issue has been patched in version 5.20.1. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-64050 +1 in the same advisory: …64049 | A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbi A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template. NVD description · AI analysis pending | 7.2 group max | <1% | PoC ×2 |
| — | |
| CVE-2025-27412 +1 in the same advisory: …27411 | REDAXO is a PHP-based CMS. REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected cross-site scripting (XSS) on the page of AddOns. This vulnerability is fixed in 5.18.3. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2024-46210 | An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file. An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2024-13209 | A vulnerability was found in Redaxo CMS 5.18.1. A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2024-46209 | A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or H A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-50803 | The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileg The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-46213 +1 in the same advisory: …46212 | REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability. REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability. NVD description · AI analysis pending | 7.2 group max | 1% | PoC |
| — | |
| CVE-2024-25298 | An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php. An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2024-25301 +1 in the same advisory: …25300 | Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php. Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php. NVD description · AI analysis pending | 7.2 group max | 1% | PoC ×2 |
| — | |
| CVE-2021-39459 +1 in the same advisory: …39458 | Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting syste Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code. NVD description · AI analysis pending | 7.2 group max | 5% | PoC ×2 |
| — | |
| CVE-2018-18200 | There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4. There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2018-17831 +1 in the same advisory: …17830 | In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.p In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the frontend only if rex_list were used. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2018-15850 | An issue was discovered in REDAXO CMS 4.7.2. An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user. NVD description · AI analysis pending | 8.8 | <1% |
| — |