redaxo/source Security Advisories for 5.21.0 (1)
-
[HIGH] Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
PKSA-h751-bdn3-ptsn CVE-2026-53599 GHSA-98pp-vccm-qm25
Affected version: >=5.18.2,<5.21.1
Reported by:
GitHub