Known Vulnerabilities for products from Redaxo

Listed below are 12 of the newest known vulnerabilities associated with the vendor "Redaxo".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-39459 Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user t... 7.2 - HIGH 2021-09-09 2022-03-31
CVE-2021-39458 Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user h... 6.5 - MEDIUM 2021-09-09 2022-07-12
CVE-2018-18200 There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4. 9.8 - CRITICAL 2018-10-09 2018-11-21
CVE-2018-18199 Mediamanager in REDAXO before 5.6.4 has XSS. 6.1 - MEDIUM 2018-10-09 2018-11-21
CVE-2018-18198 The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is outpu... 6.1 - MEDIUM 2018-10-09 2018-11-21
CVE-2018-17831 In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepa... 9.8 - CRITICAL 2018-10-01 2018-11-21
CVE-2018-17830 The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not res... 5.4 - MEDIUM 2018-10-01 2018-11-15
CVE-2018-15850 An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.ph... 8.8 - HIGH 2018-08-25 2018-10-17
CVE-2016-20053 Not Provided 2026-04-04 2026-04-04
CVE-2012-3869 Cross-site scripting (XSS) vulnerability in include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows remote atta... 4.3 - MEDIUM 2012-08-13 2012-08-14
CVE-2006-2845 PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a U... 7.5 - HIGH 2006-06-06 2018-10-18
CVE-2006-2844 Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a U... 7.5 - HIGH 2006-06-06 2018-10-18
CVE-2006-2843 PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in th... 7.5 - HIGH 2006-06-06 2018-10-18

Known software with vulnerabilities from Redaxo

Type Vendor Product Version
ApplicationRedaxoRedaxo2.7.1
ApplicationRedaxoRedaxo Cms4.7.2