Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
redaxo/source REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration Medium Risk 4.3 3 days ago 3 days ago
redaxo/source REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates Medium Risk 6.4 4 days ago 4 days ago
redaxo/source REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()` Medium Risk 4.8 4 days ago 4 days ago
redaxo/source REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames Medium Risk 4.8 4 days ago 4 days ago
redaxo/source Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers High Risk 7.5 1 month ago 1 month ago
redaxo/source REDAXO has reflected XSS backend packages API via function parameter (CSRF token required) Low Risk 3.0 5 months ago 5 months ago
redaxo/source REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required) Low Risk 3.0 5 months ago 5 months ago
redaxo/source Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read High Risk 8.0 8 months ago 7 months ago
redaxo/source REDAXO CMS is vulnerable to Reflected XSS in Mediapool Info Banner via args[types] Medium Risk 6.1 10 months ago 10 months ago
redaxo/source REDAXO CMS is vulnerable to XSS through its module management component Medium Risk 4.8 10 months ago 10 months ago
redaxo/source REDAXO CMS is vulnerable to RCE attack through its template management component High Risk 7.2 10 months ago 10 months ago
redaxo/source Redaxo Core CMS Cross Site Scripting (XSS) Medium Risk 6.0 1 year ago 1 year ago
redaxo/source REDAXO allows Arbitrary File Upload in the mediapool page Medium Risk 5.4 1 year ago 1 year ago
redaxo/source REDAXO allows Authenticated Reflected Cross Site Scripting - packages installation Medium Risk 6.1 1 year ago 1 year ago
redaxo/source Stored XSS in REDAXO Medium Risk 5.4 1 year ago 1 year ago
redaxo/source REDAXO CMS Cross-site Scripting vulnerability Low Risk 3.0 1 year ago 1 year ago
redaxo/source Path traversal in redaxo Medium Risk 4.9 1 year ago 1 year ago
redaxo/source Code injection in REDAXO High Risk 7.2 2 years ago 2 years ago