VYPR
Vendor

Redaxo

Products
4
CVEs
32
Across products
35
Status
Private

Products

4

Recent CVEs

32
View all 32 CVEs →
  • CVE-2018-18200CriOct 9, 2018
    risk 0.64cvss 9.8epss 0.01

    There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.

  • CVE-2018-17831CriOct 1, 2018
    risk 0.64cvss 9.8epss 0.02

    In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the frontend only if rex_list…

  • CVE-2018-25353HigMay 23, 2026
    risk 0.57cvss 8.8epss 0.00

    Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or…

  • CVE-2016-10757HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.01

    In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.

  • CVE-2018-15850HigAug 25, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user.

  • CVE-2024-46210HigJan 10, 2025
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-46213HigOct 16, 2024
    risk 0.47cvss 7.2epss 0.01

    REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.

  • CVE-2024-25298HigFeb 17, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.

  • CVE-2024-25301HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

  • CVE-2021-39459HigSep 9, 2021
    risk 0.47cvss 7.2epss 0.05

    Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.

  • CVE-2018-25319HigMay 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Attackers can send GET requests to the event_add.php page with malicious…

  • CVE-2026-53599HigJul 31, 2026
    risk 0.42cvss 7.5epss 0.00

    REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg,…

  • CVE-2021-39458MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

  • CVE-2025-64050HigNov 25, 2025
    risk 0.40cvss 7.2epss 0.01

    A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors…

  • CVE-2025-27412MedMar 5, 2025
    risk 0.40cvss 6.1epss 0.00

    REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected cross-site scripting (XSS) on the page of AddOns. This vulnerability is fixed in 5.18.3.

  • CVE-2018-18199MedOct 9, 2018
    risk 0.40cvss 6.1epss 0.01

    Mediamanager in REDAXO before 5.6.4 has XSS.

  • CVE-2018-18198MedOct 9, 2018
    risk 0.40cvss 6.1epss 0.01

    The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request.

  • CVE-2026-21857MedJan 7, 2026
    risk 0.35cvss 6.5epss 0.01

    REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backup addon does not validate the `EXPDIR`…

  • CVE-2024-46209MedJan 6, 2025
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.

  • CVE-2024-50803MedNov 19, 2024
    risk 0.35cvss 5.4epss 0.01

    The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges