📦 Redaxo

by Redaxo

🔍 What is Redaxo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-64050

HIGH CVSS 7.2 Nov 25, 2025

A Remote Code Execution vulnerability in REDAXO CMS 5.20.0 allows authenticated administrators to inject PHP code into templates, which executes when visitors access frontend pages. This enables attac...

CVE-2024-46210

HIGH CVSS 7.2 Jan 10, 2025

An arbitrary file upload vulnerability in Redaxo CMS v5.17.1 allows attackers to upload malicious files through the MediaPool module. This can lead to remote code execution on affected systems. All Re...

CVE-2024-46213

HIGH CVSS 7.2 Oct 16, 2024

REDAXO CMS v2.11.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code on affected systems. This affects all installations running the vulnerable version, po...

CVE-2024-25298

HIGH CVSS 7.2 Feb 17, 2024

CVE-2024-25298 is a critical code injection vulnerability in REDAXO CMS version 5.15.1 that allows attackers to execute arbitrary code on affected systems. The vulnerability exists in modules.modules....

CVE-2024-25301

HIGH CVSS 7.2 Feb 14, 2024

CVE-2024-25301 is a remote code execution vulnerability in Redaxo CMS v5.15.1 that allows attackers to execute arbitrary code via the /pages/templates.php component. This affects all systems running t...

CVE-2021-39459

HIGH CVSS 7.2 Sep 9, 2021

This vulnerability allows authenticated users in Redaxo CMS to execute arbitrary PHP code on the server by uploading malicious modules. It affects Redaxo CMS administrators and users with module uploa...

CVE-2026-21857

MEDIUM CVSS 6.5 Jan 7, 2026

This vulnerability allows authenticated REDAXO users with backup permissions to read arbitrary files within the webroot via path traversal in the Backup addon. Attackers can manipulate the EXPDIR para...

CVE-2025-66026

MEDIUM CVSS 6.1 Nov 26, 2025

This is a reflected Cross-Site Scripting (XSS) vulnerability in REDAXO CMS that allows arbitrary JavaScript execution in the backend when authenticated users click malicious links. Attackers can steal...

CVE-2025-64049

MEDIUM CVSS 4.8 Nov 25, 2025

A stored cross-site scripting (XSS) vulnerability in REDAXO CMS 5.20.0 allows remote authenticated users to inject malicious scripts into the module management component. When other users view or edit...

CVE-2025-27412

MEDIUM CVSS 6.1 Mar 5, 2025

CVE-2025-27412 is a reflected cross-site scripting (XSS) vulnerability in REDAXO CMS that allows attackers to inject malicious scripts via the rex-api-result parameter. This affects administrators and...

CVE-2024-46209

MEDIUM CVSS 5.4 Jan 6, 2025

A stored cross-site scripting (XSS) vulnerability in REDAXO CMS v5.17.1 allows attackers to inject malicious scripts into the password parameter of the /media/test.html component. This enables executi...

CVE-2024-50803

MEDIUM CVSS 5.4 Nov 19, 2024

CVE-2024-50803 is a cross-site scripting (XSS) vulnerability in Redaxo CMS's mediapool feature that allows attackers to inject malicious scripts. This affects Redaxo CMS administrators who can access ...