CVE-2026-53599 | Redaxo up to 5.21.0 Mediapool mediapool.php isAllowedExtension unrestricted upload

SecurityVulns

A vulnerability has been found in Redaxo up to 5.21.0 and classified as problematic. This affects the function rex_mediapool::isAllowedExtension of the file redaxo/src/addons/mediapool/lib/mediapool.php of the component Mediapool. This manipulation causes unrestricted upload.

The identification of this vulnerability is CVE-2026-53599. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More