ZeroHour

Vulnerabilities

24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-20053
Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking auth

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the users endpoint with hidden fields containing admin credentials and account parameters to add new administrator accounts without user consent.

NVD description · AI analysis pending
6.9<1% PoC
  • redaxo redaxo
CVE-2026-21857
REDAXO is a PHP-based content management system.

REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backup addon does not validate the `EXPDIR` POST parameter against the UI-generated allowlist of permitted directories. An attacker can supply relative paths containing `../` sequences (or even absolute paths inside the document root) to include any readable file in the generated `.tar.gz` archive. Version 5.20.2 fixes this issue.

NVD description · AI analysis pending
8.3<1% PoC
  • redaxo redaxo
CVE-2025-66026
REDAXO is a PHP-based CMS.

REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the Mediapool view where the request parameter args[types] is rendered into an info banner without HTML-escaping. This allows arbitrary JavaScript execution in the backend context when an authenticated user visits a crafted link while logged in. This issue has been patched in version 5.20.1.

NVD description · AI analysis pending
6.1<1% PoC
  • redaxo redaxo
CVE-2025-64050
+1 in the same advisory: …64049
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbi

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.

NVD description · AI analysis pending
7.2
group max
<1% PoC ×2
  • redaxo redaxo
CVE-2025-27412
+1 in the same advisory: …27411
REDAXO is a PHP-based CMS.

REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected cross-site scripting (XSS) on the page of AddOns. This vulnerability is fixed in 5.18.3.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • redaxo redaxo
CVE-2024-46210
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

NVD description · AI analysis pending
7.2<1%
  • redaxo redaxo
CVE-2024-13209
A vulnerability was found in Redaxo CMS 5.18.1.

A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.1<1% PoC
  • redaxo redaxo
CVE-2024-46209
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or H

A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • redaxo redaxo
CVE-2024-50803
The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileg

The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges

NVD description · AI analysis pending
5.4<1%
  • redaxo redaxo
CVE-2024-46213
+1 in the same advisory: …46212
REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.

REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.

NVD description · AI analysis pending
7.2
group max
1% PoC
  • redaxo redaxo
CVE-2024-25298
An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.

An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.

NVD description · AI analysis pending
7.21% PoC
  • redaxo redaxo
CVE-2024-25301
+1 in the same advisory: …25300
Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

NVD description · AI analysis pending
7.2
group max
1% PoC ×2
  • redaxo redaxo
CVE-2021-39459
+1 in the same advisory: …39458
Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting syste

Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.

NVD description · AI analysis pending
7.2
group max
5% PoC ×2
  • redaxo redaxo
CVE-2018-18200
+2 in the same advisory: …18198 …18199
There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.

There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.

NVD description · AI analysis pending
9.8
group max
1%
  • redaxo redaxo
CVE-2018-17831
+1 in the same advisory: …17830
In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.p

In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the frontend only if rex_list were used.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • redaxo redaxo
CVE-2018-15850
An issue was discovered in REDAXO CMS 4.7.2.

An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user.

NVD description · AI analysis pending
8.8<1%
  • redaxo redaxo cms