Known Vulnerabilities for products from Redaxo
Listed below are 13 of the newest known vulnerabilities associated with the vendor "Redaxo".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-39459 json | Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user t... | 7.2 - HIGH | 2021-09-09 | 2022-03-31 |
| CVE-2021-39458 json | Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user h... | 6.5 - MEDIUM | 2021-09-09 | 2022-07-12 |
| CVE-2018-18200 json | There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4. | 9.8 - CRITICAL | 2018-10-09 | 2018-11-21 |
| CVE-2018-18199 json | Mediamanager in REDAXO before 5.6.4 has XSS. | 6.1 - MEDIUM | 2018-10-09 | 2018-11-21 |
| CVE-2018-18198 json | The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is outpu... | 6.1 - MEDIUM | 2018-10-09 | 2018-11-21 |
| CVE-2018-17831 json | In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepa... | 9.8 - CRITICAL | 2018-10-01 | 2018-11-21 |
| CVE-2018-17830 json | The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not res... | 5.4 - MEDIUM | 2018-10-01 | 2018-11-15 |
| CVE-2018-15850 json | An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.ph... | 8.8 - HIGH | 2018-08-25 | 2018-10-17 |
| CVE-2016-20053 json | Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administra... | Not Provided | 2026-04-04 | 2026-04-14 |
| CVE-2012-3869 json | Cross-site scripting (XSS) vulnerability in include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows remote atta... | 4.3 - MEDIUM | 2012-08-13 | 2012-08-14 |
| CVE-2006-2845 json | PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a U... | 7.5 - HIGH | 2006-06-06 | 2018-10-18 |
| CVE-2006-2844 json | Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a U... | 7.5 - HIGH | 2006-06-06 | 2018-10-18 |
| CVE-2006-2843 json | PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in th... | 7.5 - HIGH | 2006-06-06 | 2018-10-18 |
Known software with vulnerabilities from Redaxo
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Redaxo | Redaxo | 2.7.1 |
| Application | Redaxo | Redaxo Cms | 4.7.2 |