CVE-2025-64050
REDAXO CMS is vulnerable to RCE attack through its template management component
7.2
HIGH
CVSS 3.1
EPSS 0.79%
Description
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.
How to fix CVE-2025-64050
To remediate CVE-2025-64050, upgrade the affected package to a fixed version below.
- —upgrade to 5.20.1 or later
Is CVE-2025-64050 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.20.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |