PHP-Based Content Management System Vulnerability in REDAXO
CVE-2026-53599
7.5HIGH
What is CVE-2026-53599?
REDAXO, a PHP-based content management system, has a vulnerability that allows authenticated backend users with media upload permissions to upload potentially malicious files in the form of a JPEG/PHP polyglot named 'shell.php.any.jpg'. This file could be executed by web servers configured with multi-extension PHP handlers, enabling unauthorized access to the web server. The issue exists in versions 5.18.2 through 5.21.0 and has been addressed in version 5.21.1, which users are recommended to upgrade to in order to mitigate this risk.
Affected Version(s)
core >= 5.18.2, < 5.21.1
