Webedition develops a content-management system that, despite a narrow product portfolio, ranks among the more prominent targets in its category and presents a meaningful attack surface through web application interfaces. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with recurrent exposure centered on input-handling and code-generation weaknesses including code injection, path traversal, cross-site scripting, and SQL injection that are characteristic of web-application platforms. Defenders should treat this vendor's updates as priority for internet-facing instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webedition over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5258MEDIUM Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file | Nov 6, 2014 | 4.0 | 43 | NO | YES |
CVE-2014-2302CRITICAL The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update | Jul 19, 2018 | 9.8 | 32 | NO | NO |
CVE-2014-2303HIGH Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to ex | Jun 13, 2014 | 7.5 | 29 | NO | YES |
CVE-2023-53883HIGH Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create | Dec 15, 2025 | 7.2 | 24 | NO | NO |
CVE-2009-1222MEDIUM Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to incl | Apr 2, 2009 | 5.1 | 23 | NO | YES |
CVE-2023-53884MEDIUM Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can u | Dec 15, 2025 | 5.4 | 20 | NO | NO |
CVE-2024-28418MEDIUM Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php | Mar 14, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-28417MEDIUM Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php. | Mar 14, 2024 | 6.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webedition.
Media articles that mention a CVE ID that affects a product developed by Webedition — matched by CVE ID, not by vendor name.