REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker who can place an unregist
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63000 | 6.4 MEDIUM | REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates |
| CVE-2026-63001 | 4.8 MEDIUM | REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()` |
| CVE-2026-62998 | 4.3 MEDIUM | REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration |
No comments yet