Vulnerabilities (CVE)

Filtered by vendor Redaxo Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-39459 1 Redaxo 1 Redaxo 2022-01-10 9.0 HIGH 7.2 HIGH
Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.
CVE-2018-15850 1 Redaxo 1 Redaxo Cms 2018-10-17 6.8 MEDIUM 8.8 HIGH
An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user.