AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-53599 was published on 2026-07-31T20:16:51.847Z and has not been modified since then. This high-severity vulnerability affects REDAXO content management system versions from 5.18.2 to 5.21.1. An authenticated backend user with media upload permission can upload a malicious JPEG/PHP polyglot file, such as shell. [truncated]
A high-severity arbitrary file upload vulnerability in Redaxo CMS Mediapool Addon 5.5.1 and older allows authenticated users with editor privileges to bypass file extension blacklist restrictions. The vulnerability stems from insufficient validation of file extensions, permitting attackers to use obfuscated extensions such as php71 or php53 to evade the blacklist filter and upload executable files. Succes [truncated]
CVE-2016-20053 is a cross-site request forgery vulnerability in Redaxo CMS 5.2. This vulnerability allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. The vulnerability exists in the users endpoint of Redaxo CMS 5.2. Attackers can craft HTML forms with hidden fields containing admin credentials and account paramete [truncated]