redaxo/source
REDAXO CMS source repository (for static analysis)
Security Advisories for redaxo/source in packagist
High
27 days ago
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
packagist
redaxo/source
Low
5 months ago
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
packagist
redaxo/source
Low
5 months ago
REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required)
packagist
redaxo/source
High
8 months ago
Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read
packagist
redaxo/source
Moderate
9 months ago
REDAXO CMS is vulnerable to Reflected XSS in Mediapool Info Banner via args[types]
packagist
redaxo/source
Moderate
9 months ago
REDAXO CMS is vulnerable to XSS through its module management component
packagist
redaxo/source
High
9 months ago
REDAXO CMS is vulnerable to RCE attack through its template management component
packagist
redaxo/source
Moderate
over 1 year ago
REDAXO allows Authenticated Reflected Cross Site Scripting - packages installation
packagist
redaxo/source
Moderate
over 1 year ago
REDAXO allows Arbitrary File Upload in the mediapool page
packagist
redaxo/source