Redaxo/source
13 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Redaxo/source, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Redaxo/source CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 0 |
| 2025-03 | 2 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 3 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High2
- Medium8
- Low1
Latest CVEs
The 13 most recently published vulnerabilities affecting Redaxo/source.
- GHSA-xq4j-g85q-wf97REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)—
- GHSA-m662-8jrj-cw6vREDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required)—
- CVE-2026-21857Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read6.5
- CVE-2025-66026REDAXO is Vulnerable to Reflected XSS in Mediapool Info Banner via args[types]6.1
- CVE-2025-64049A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in mod...4.8
- CVE-2025-64050A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by in...7.2
- CVE-2025-27412REDAXO allows Authenticated Reflected Cross Site Scripting - packages installation6.1
- CVE-2025-27411REDAXO allows Arbitrary File Upload in the mediapool page5.4
- CVE-2024-13209Redaxo CMS Structure Management Page index.php cross site scripting2.4
- CVE-2024-46209A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload i...5.4
- CVE-2024-50803The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges5.4
- CVE-2024-46212An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.4.9
- CVE-2024-25298An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.7.2
Product grouping is registry-driven, with AI assist and human review. How it works