Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-25298

Disclosure Date: February 17, 2024 (last updated February 26, 2025)
An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.
Attacker Value
Unknown

CVE-2024-25301

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.
Attacker Value
Unknown

CVE-2024-25300

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Template section.