redaxo/source Security Advisories for 5.15.1 (7)
- 
                        [MEDIUM] REDAXO allows Authenticated Reflected Cross Site Scripting - packages installationPKSA-76dy-z23y-9p4c CVE-2025-27412 GHSA-8366-xmgf-334f Affected version: >=5.0.0,<5.18.3 Reported by: 
 GitHub
- 
                        [MEDIUM] REDAXO allows Arbitrary File Upload in the mediapool pagePKSA-t5ch-tqpp-j3n9 CVE-2025-27411 GHSA-wppf-gqj5-fc4f Affected version: <5.18.3 Reported by: 
 GitHub
- 
                        [MEDIUM] Stored XSS in REDAXOPKSA-njhr-8v9z-nrm1 CVE-2024-13209 GHSA-7wj8-856p-qc9m Affected version: >=5.12.0-beta1,<=5.18.1 Reported by: 
 GitHub
- 
                        [LOW] REDAXO CMS Cross-site Scripting vulnerabilityPKSA-r1p5-d5cc-v5v1 CVE-2024-46209 GHSA-2p95-8xvm-2pjx Affected version: <=5.17.1 Reported by: 
 GitHub
- 
                        [MEDIUM] Redaxo Core CMS Cross Site Scripting (XSS)PKSA-dp3c-dd93-8dhf CVE-2024-50803 GHSA-m5vv-7jxc-8p6x Affected version: <5.18.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Path traversal in redaxoPKSA-v8r2-shtd-c5bm CVE-2024-46212 GHSA-37gm-h5wr-pf25 Affected version: <=5.17.1 Reported by: 
 GitHub
- 
                        [HIGH] Code injection in REDAXOPKSA-8xbx-ff98-hq82 CVE-2024-25298 GHSA-7f2v-5877-rx3x Affected version: <=5.15.1 Reported by: 
 GitHub