CVE-2026-63001: REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`
A stored cross-site scripting (XSS) vulnerability exists in REDAXO CMS 5.x. When an administrator attempts to delete a media file that is referenced by a Media Manager effect, the warning message rendered in the backend includes the type’s name field without HTML escaping. An attacker with access to the Media Manager addon can store an XSS payload as a type name; the payload executes in the browser of any administrator who subsequently tries to delete a media file linked to that type’s effects. This can lead to session hijacking and full backend account takeover.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-63001 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →