If you discover a security issue with REDAXO or a related package, please
contact us via https://github.com/redaxo/core/security/advisories/new or
info {at} redaxo.org instead of using a public channel. That way we can work
on a fix together before everyone knows how to exploit a potential issue. Thank
you!
Security: redaxo/core
Security
SECURITY.md
-
Working version and history previews do not verify permissions for the previewed articleGHSA-v4m9-jvvr-83cx published
Aug 3, 2026 by gharlanHigh -
Media pool bulk move does not verify permission for the source categoryGHSA-j9mx-x52f-48cw published
Aug 3, 2026 by gharlanHigh -
Slice operations do not verify that the slice belongs to the permission checked articleGHSA-5m63-c3qx-wq8v published
Aug 3, 2026 by gharlanHigh -
Stored cross-site scripting (XSS) in the media and link input widgetsGHSA-5wmj-5x79-rr87 published
Aug 3, 2026 by gharlanModerate -
Authentication bypass via forgeable temporary login token in the history pluginGHSA-px8f-whj8-hrpq published
Aug 3, 2026 by gharlanCritical -
Mediapool: unsanitized SVG uploads are publicly reachable, enabling stored XSSGHSA-2p3g-jr7p-qwwx published
Aug 3, 2026 by gharlanModerate -
Missing CSRF protection in the article history plugin allows history deletion and content rollbackGHSA-vjwx-3c33-xwmc published
Jul 31, 2026 by gharlanModerate -
Reflected cross-site scripting in the media pool via the opener_link parameterGHSA-5293-gg47-5xmh published
Jul 31, 2026 by gharlanModerate -
CSRF token check bypass in the user administration allows privilege escalationGHSA-mrrj-4f5x-j958 published
Jul 31, 2026 by gharlanHigh -
Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column EnumerationGHSA-4f5f-j737-pm58 published
Jun 29, 2026 by gharlanModerate
Learn more about advisories related to redaxo/core in the GitHub Advisory Database