CVE-2025-64049

A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in modules. The payload is executed when a user views or edits an article by adding slice that uses the compromised module.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redaxo:redaxo:5.20.0:*:*:*:*:*:*:*

History

03 Dec 2025, 17:06

Type Values Removed Values Added
References () https://drive.google.com/drive/folders/1SpwL548ZBRYU_uL8W7Riv7VHshr2UN0R?usp=sharing - () https://drive.google.com/drive/folders/1SpwL548ZBRYU_uL8W7Riv7VHshr2UN0R?usp=sharing - Exploit
References () https://github.com/redaxo/redaxo - () https://github.com/redaxo/redaxo - Product
References () https://github.com/vettrivel007/CVE-Disclosures/blob/main/CVE-2025-64049.md - () https://github.com/vettrivel007/CVE-Disclosures/blob/main/CVE-2025-64049.md - Exploit, Mitigation, Third Party Advisory
First Time Redaxo
Redaxo redaxo
CPE cpe:2.3:a:redaxo:redaxo:5.20.0:*:*:*:*:*:*:*

25 Nov 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 16:16

Updated : 2025-12-03 17:06


NVD link : CVE-2025-64049

Mitre link : CVE-2025-64049

CVE.ORG link : CVE-2025-64049


JSON object : View

Products Affected

redaxo

  • redaxo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')