Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webedition

First CVE: Apr 2, 2009Active for: 17 yearsTotal CVEs: 8

Webedition develops a content-management system that, despite a narrow product portfolio, ranks among the more prominent targets in its category and presents a meaningful attack surface through web application interfaces. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with recurrent exposure centered on input-handling and code-generation weaknesses including code injection, path traversal, cross-site scripting, and SQL injection that are characteristic of web-application platforms. Defenders should treat this vendor's updates as priority for internet-facing instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webedition over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 2, 2009
17 years ago
Most Recent CVE
Dec 15, 2025
221 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-5258MEDIUM
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file
Nov 6, 20144.043NOYES
CVE-2014-2302CRITICAL
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update
Jul 19, 20189.832NONO
CVE-2014-2303HIGH
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to ex
Jun 13, 20147.529NOYES
CVE-2023-53883HIGH
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create
Dec 15, 20257.224NONO
CVE-2009-1222MEDIUM
Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to incl
Apr 2, 20095.123NOYES
CVE-2023-53884MEDIUM
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can u
Dec 15, 20255.420NONO
CVE-2024-28418MEDIUM
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
Mar 14, 20246.518NONO
CVE-2024-28417MEDIUM
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
Mar 14, 20246.318NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
63%
25%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (62.5%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High0 (0.0%)
Unknown3 (37.5%)
User Interaction
None3 (37.5%)
Unknown3 (37.5%)
Required2 (25.0%)
Privileges Required
Low2 (25.0%)
High1 (12.5%)
None2 (25.0%)
Unknown3 (37.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
3 CVEs
37.5% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webedition.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webedition — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webedition's Products

View all 2 CNAs →

Top CWEs