Vulnerabilities
Vulnerable Software
Redaxo:  >> Redaxo  >> 5.20.0  Security Vulnerabilities
A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in modules. The payload is executed when a user views or edits an article by adding slice that uses the compromised module.
CVSS Score
4.8
EPSS Score
0.0
Published
2025-11-25
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
CVSS Score
7.2
EPSS Score
0.003
Published
2025-11-25


Contact Us

Shodan ® - All rights reserved