CVE-2025-64049
REDAXO CMS is vulnerable to XSS through its module management component
4.8
MEDIUM
CVSS 3.1
EPSS 0.26%
Description
A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in modules. The payload is executed when a user views or edits an article by adding slice that uses the compromised module.
How to fix CVE-2025-64049
To remediate CVE-2025-64049, upgrade the affected package to a fixed version below.
- —upgrade to 5.20.1 or later
Is CVE-2025-64049 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.20.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |