HIGH🇵🇱 Wersja polska

CVE-2025-64050

CVSS 7.2v3.1pub. 2025-11-25upd. 2025-12-03

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Redaxo

    APP
    Redaxo
    5.20.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-18200CRITICAL9.8PL ✓same product

SQL injection w module Benutzerverwaltung systemu REDAXO CMS

CVE-2018-17831CRITICAL9.8PL ✓same product

SQL injection w REDAXO CMS — parametr sort w klasie rex_list

CVE-2026-21857HIGH8.3same product

REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup perm...

CVE-2024-46210HIGH7.2same product

An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execu...

CVE-2024-46213HIGH7.2same product

REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.