CVE-2023-53883
- EPSS 0.34%
- Veröffentlicht 15.12.2025 20:28:20
- Zuletzt bearbeitet 16.12.2025 14:10:11
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description fiel...
CVE-2023-53884
- EPSS 0.06%
- Veröffentlicht 15.12.2025 20:28:20
- Zuletzt bearbeitet 16.12.2025 14:10:11
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and...
CVE-2024-28417
- EPSS 0.08%
- Veröffentlicht 14.03.2024 13:15:53
- Zuletzt bearbeitet 30.04.2025 23:58:26
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
CVE-2024-28418
- EPSS 0.14%
- Veröffentlicht 14.03.2024 13:15:53
- Zuletzt bearbeitet 30.04.2025 23:57:59
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
CVE-2014-2302
- EPSS 10.76%
- Veröffentlicht 19.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 02:06:02
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.
- EPSS 81.94%
- Veröffentlicht 06.11.2014 18:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2014-2303
- EPSS 3.2%
- Veröffentlicht 13.06.2014 14:55:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.