redaxo CVE Vulnerabilities & Metrics

Focus on redaxo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About redaxo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with redaxo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total redaxo CVEs: 11
Earliest CVE date: 06 Jun 2006, 20:06 UTC
Latest CVE date: 17 Feb 2024, 06:15 UTC

Latest CVE reference: CVE-2024-25298

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical redaxo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.91

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 5
7.0-8.9 5
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS redaxo CVEs

These are the five CVEs with the highest CVSS scores for redaxo, sorted by severity first and recency.

All CVEs for redaxo

CVE-2024-25298 redaxo vulnerability CVSS: 0 17 Feb 2024, 06:15 UTC

An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.

CVE-2024-25301 redaxo vulnerability CVSS: 0 14 Feb 2024, 19:15 UTC

Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

CVE-2024-25300 redaxo vulnerability CVSS: 0 14 Feb 2024, 19:15 UTC

A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Template section.

CVE-2021-39459 redaxo vulnerability CVSS: 9.0 09 Sep 2021, 12:15 UTC

Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.

CVE-2021-39458 redaxo vulnerability CVSS: 4.0 09 Sep 2021, 12:15 UTC

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

CVE-2018-18200 redaxo vulnerability CVSS: 7.5 09 Oct 2018, 22:29 UTC

There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.

CVE-2018-18199 redaxo vulnerability CVSS: 4.3 09 Oct 2018, 22:29 UTC

Mediamanager in REDAXO before 5.6.4 has XSS.

CVE-2018-18198 redaxo vulnerability CVSS: 4.3 09 Oct 2018, 22:29 UTC

The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request.

CVE-2018-17831 redaxo vulnerability CVSS: 7.5 01 Oct 2018, 08:29 UTC

In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the frontend only if rex_list were used.

CVE-2018-17830 redaxo vulnerability CVSS: 3.5 01 Oct 2018, 08:29 UTC

The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring.

CVE-2018-15850 redaxo vulnerability CVSS: 6.8 25 Aug 2018, 21:29 UTC

An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user.

CVE-2012-3869 redaxo vulnerability CVSS: 4.3 13 Aug 2012, 20:55 UTC

Cross-site scripting (XSS) vulnerability in include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows remote attackers to inject arbitrary web script or HTML via the subpage parameter to index.php.

CVE-2006-2843 redaxo vulnerability CVSS: 7.5 06 Jun 2006, 20:06 UTC

PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDE_PATH] parameter in (a) addons/import_export/pages/index.inc.php and (b) pages/community.inc.php.

CVE-2006-2844 redaxo vulnerability CVSS: 7.5 06 Jun 2006, 20:06 UTC

Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to (1) simple_user/pages/index.inc.php and (2) stats/pages/index.inc.php.

CVE-2006-2845 redaxo vulnerability CVSS: 7.5 06 Jun 2006, 20:06 UTC

PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to image_resize/pages/index.inc.php.