redaxo
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting redaxo.
- CVE-2018-25353Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload8.8
- CVE-2016-20053Redaxo CMS 5.2 Cross-Site Request Forgery via users endpoint5.3
- CVE-2026-21857Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read6.5
- CVE-2025-66026REDAXO is Vulnerable to Reflected XSS in Mediapool Info Banner via args[types]6.1
- CVE-2025-64049A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in mod...4.8
- CVE-2025-64050A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by in...7.2
- CVE-2025-27412REDAXO allows Authenticated Reflected Cross Site Scripting - packages installation6.1
- CVE-2025-27411REDAXO allows Arbitrary File Upload in the mediapool page5.4
- CVE-2024-46210An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.7.2
- CVE-2024-13209Redaxo CMS Structure Management Page index.php cross site scripting2.4
- CVE-2024-46209A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload i...5.4
- CVE-2024-50803The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges5.4
- CVE-2024-46212An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.4.9
- CVE-2024-46213REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.7.2
- CVE-2024-25298An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.7.2