PatchSiren

redaxo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH redaxo CVE published 2026-07-31

CVE-2026-53599

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-53599 was published on 2026-07-31T20:16:51.847Z and has not been modified since then. This high-severity vulnerability affects REDAXO content management system versions from 5.18.2 to 5.21.1. An authenticated backend user with media upload permission can upload a malicious JPEG/PHP polyglot file, such as shell. [truncated]

HIGH Redaxo CVE published 2026-05-23

CVE-2018-25353

A high-severity arbitrary file upload vulnerability in Redaxo CMS Mediapool Addon 5.5.1 and older allows authenticated users with editor privileges to bypass file extension blacklist restrictions. The vulnerability stems from insufficient validation of file extensions, permitting attackers to use obfuscated extensions such as php71 or php53 to evade the blacklist filter and upload executable files. Succes [truncated]

MEDIUM Redaxo CVE published 2026-04-04

CVE-2016-20053

CVE-2016-20053 is a cross-site request forgery vulnerability in Redaxo CMS 5.2. This vulnerability allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. The vulnerability exists in the users endpoint of Redaxo CMS 5.2. Attackers can craft HTML forms with hidden fields containing admin credentials and account paramete [truncated]