← Back

Webedition Cms

webedition_cms

Vendor: Webedition • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webedition
1Webedition Cms
Dec 18, 2025
Dec 15, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the medi...Show more
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.Show less
1Webedition
1Webedition Cms
Dec 18, 2025
Dec 15, 2025
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system co...Show more
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.Show less
1Webedition
1Webedition Cms
Apr 30, 2025
Mar 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
1Webedition
1Webedition Cms
Apr 30, 2025
Mar 14, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
1Webedition
1Webedition Cms
Nov 21, 2024
Jul 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.
1Webedition
1Webedition Cms
May 6, 2026
Nov 6, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.
1Webedition
1Webedition Cms
May 6, 2026
Jun 13, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1)...Show more
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.Show less