CVE-2025-64050

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redaxo:redaxo:5.20.0:*:*:*:*:*:*:*

History

03 Dec 2025, 17:06

Type Values Removed Values Added
CPE cpe:2.3:a:redaxo:redaxo:5.20.0:*:*:*:*:*:*:*
References () https://drive.google.com/drive/folders/1Via4r4wn5zCcBllWmHpxYweCPgcbN0bz?usp=sharing - () https://drive.google.com/drive/folders/1Via4r4wn5zCcBllWmHpxYweCPgcbN0bz?usp=sharing - Exploit
References () https://github.com/redaxo/redaxo - () https://github.com/redaxo/redaxo - Product
References () https://github.com/vettrivel007/CVE-Disclosures/blob/main/CVE-2025-64050.md - () https://github.com/vettrivel007/CVE-Disclosures/blob/main/CVE-2025-64050.md - Exploit, Third Party Advisory
First Time Redaxo
Redaxo redaxo

25 Nov 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 16:16

Updated : 2025-12-03 17:06


NVD link : CVE-2025-64050

Mitre link : CVE-2025-64050

CVE.ORG link : CVE-2025-64050


JSON object : View

Products Affected

redaxo

  • redaxo
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')