Cross-Site Scripting in REDAXO Media Manager
CVE-2026-63001

4.8MEDIUM

Key Information:

Vendor

Redaxo

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-63001?

The REDAXO content management system contains a cross-site scripting vulnerability in its Media Manager component. Specifically, versions prior to 5.21.2 contain a flaw in the mediaIsInUse() handler, which fails to properly escape media type names inserted into administrative backend HTML. This oversight allows an administrator with Media Manager privileges to store malicious HTML within a type name. As a result, when another administrator attempts to delete media linked to this type, the injected HTML is executed in their browser context. This can lead to session hijacking or unauthorized actions within the backend environment. Users are encouraged to upgrade to version 5.21.2 or later to mitigate these risks.

Affected Version(s)

core < 5.21.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.