Vulnerabilities
Vulnerable Software
Webedition:  Security Vulnerabilities
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.
CVSS Score
8.6
EPSS Score
0.005
Published
2025-12-15
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.
CVSS Score
5.1
EPSS Score
0.001
Published
2025-12-15
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-03-14
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
CVSS Score
6.5
EPSS Score
0.002
Published
2024-03-14
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.
CVSS Score
9.8
EPSS Score
0.019
Published
2018-07-19
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.
CVSS Score
4.0
EPSS Score
0.812
Published
2014-11-06
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.
CVSS Score
7.5
EPSS Score
0.041
Published
2014-06-13
Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the WE_LANGUAGE parameter.
CVSS Score
5.1
EPSS Score
0.032
Published
2009-04-02


Contact Us

Shodan ® - All rights reserved