PatchSiren

redaxo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM redaxo CVE published 2026-09-23

CVE-2026-63000

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-23T15:17:15.453Z and has not been modified since then. This CSRF vulnerability in REDAXO versions prior to 5.21.2 allows an unauthenticated attacker to cause a logged-in administrator's browser to request a selected package update, potentially changing installed addon code or disrupting the site. De [truncated]

HIGH redaxo CVE published 2026-07-31

CVE-2026-53599

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-53599 was published on 2026-07-31T20:16:51.847Z and has not been modified since then. This high-severity vulnerability affects REDAXO content management system versions from 5.18.2 to 5.21.1. An authenticated backend user with media upload permission can upload a malicious JPEG/PHP polyglot file, such as shell. [truncated]

HIGH Redaxo CVE published 2026-05-23

CVE-2018-25353

A high-severity arbitrary file upload vulnerability in Redaxo CMS Mediapool Addon 5.5.1 and older allows authenticated users with editor privileges to bypass file extension blacklist restrictions. The vulnerability stems from insufficient validation of file extensions, permitting attackers to use obfuscated extensions such as php71 or php53 to evade the blacklist filter and upload executable files. Succes [truncated]

MEDIUM Redaxo CVE published 2026-04-04

CVE-2016-20053

CVE-2016-20053 is a cross-site request forgery vulnerability in Redaxo CMS 5.2. This vulnerability allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. The vulnerability exists in the users endpoint of Redaxo CMS 5.2. Attackers can craft HTML forms with hidden fields containing admin credentials and account paramete [truncated]