Vulnerabilities
Vulnerable Software
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.
CVSS Score
7.2
EPSS Score
0.002
Published
2025-12-15
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-12-15


Contact Us

Shodan ® - All rights reserved