Webedition records
8 published records for vendor webedition.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2014-2302No exploit | The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attwebedition · webedition cms · CWE-94 | Critical9.8 | — | 4.5% | Jul 19, 2018 |
34Monitor | CVE-2023-53883No exploit | Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creationwebedition · webedition cms · CWE-94 | High8.6 | — | 1.0% | Dec 15, 2025 |
31Monitor | CVE-2014-2303Proof of concept | Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8webedition · webedition cms · CWE-89 | High7.5 | — | 2.6% | Jun 13, 2014 |
26Monitor | CVE-2024-28418No exploit | Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.phpwebedition · webedition cms · CWE-434 | Medium6.5 | — | 0.4% | Mar 14, 2024 |
25Monitor | CVE-2024-28417No exploit | Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.webedition · webedition cms · CWE-80 | Medium6.3 | — | 0.3% | Mar 14, 2024 |
22Monitor | CVE-2014-5258Proof of concept | Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrwebedition · webedition cms · CWE-22 | Medium4.0 | — | 20.3% | Nov 6, 2014 |
21Monitor | CVE-2009-1222Proof of concept | Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is dwebedition · webedition · CWE-22 | Medium5.1 | — | 2.0% | Apr 2, 2009 |
20Monitor | CVE-2023-53884No exploit | Webedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Uploadwebedition · webedition cms · CWE-79 | Medium5.1 | — | 0.3% | Dec 15, 2025 |
- CVE-2014-230240Plan
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection att
CriticalCVSS 9.8No exploitEPSS 4%webedition · webedition cmsJul 19, 2018
- CVE-2023-5388334Monitor
Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creation
HighCVSS 8.6No exploitEPSS 1%webedition · webedition cmsDec 15, 2025
- CVE-2014-230331Monitor
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8
HighCVSS 7.5Proof of conceptEPSS 3%webedition · webedition cmsJun 13, 2014
- CVE-2024-2841826Monitor
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
MediumCVSS 6.5No exploitEPSS 0%webedition · webedition cmsMar 14, 2024
- CVE-2024-2841725Monitor
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
MediumCVSS 6.3No exploitEPSS 0%webedition · webedition cmsMar 14, 2024
- CVE-2014-525822Monitor
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitr
MediumCVSS 4.0Proof of conceptEPSS 20%webedition · webedition cmsNov 6, 2014
- CVE-2009-122221Monitor
Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is d
MediumCVSS 5.1Proof of conceptEPSS 2%webedition · webeditionApr 2, 2009
- CVE-2023-5388420Monitor
Webedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Upload
MediumCVSS 5.1No exploitEPSS 0%webedition · webedition cmsDec 15, 2025