Modx Revolution
Modx · 36 CVEs
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which…
Oct 31, 2021
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is:…
Jul 23, 2019
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
Feb 6, 2019
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
Feb 6, 2019
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an…
Feb 6, 2019
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
Feb 6, 2019
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
Sep 26, 2018
MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.clas…
Jul 13, 2018
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before p…
Jul 13, 2018
MODX Revolution 2.6.3 has XSS.
Jun 1, 2018
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earli…
Nov 17, 2017
Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to i…
Aug 29, 2017
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malici…
Jul 30, 2017
In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host hea…
May 18, 2017
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any…
May 18, 2017
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a f…
May 18, 2017
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields…
May 18, 2017
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on…
May 18, 2017
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution…
Apr 25, 2017
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP c…
Mar 30, 2017
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com b…
Mar 30, 2017
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certif…
Mar 30, 2017
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP…
Mar 30, 2017
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language paramet…
Mar 30, 2017
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform loca…
Dec 24, 2016
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-25911 | A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure o… | CRITICAL | 2.38% | Oct 31, 2021 |
| CVE-2019-1010123 | MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and… | HIGH | 1.19% | Jul 23, 2019 |
| CVE-2018-20758 | MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description. | MEDIUM | 0.61% | Feb 6, 2019 |
| CVE-2018-20757 | MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name. | MEDIUM | 0.86% | Feb 6, 2019 |
| CVE-2018-20756 | MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or… | MEDIUM | 0.86% | Feb 6, 2019 |
| CVE-2018-20755 | MODX Revolution through v2.7.0-pl allows XSS via the User Photo field. | MEDIUM | 0.86% | Feb 6, 2019 |
| CVE-2018-17556 | MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action. | MEDIUM | 0.59% | Sep 26, 2018 |
| CVE-2018-1000208 | MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. T… | HIGH | 1.92% | Jul 13, 2018 |
| CVE-2018-1000207 | MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can… | HIGH | 64.09% | Jul 13, 2018 |
| CVE-2018-10382 | MODX Revolution 2.6.3 has XSS. | MEDIUM | 0.66% | Jun 1, 2018 |
| CVE-2017-1000223 | A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissio… | MEDIUM | 0.50% | Nov 17, 2017 |
| CVE-2015-6588 | Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via t… | MEDIUM | 1.20% | Aug 29, 2017 |
| CVE-2017-11744 | In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php… | MEDIUM | 0.60% | Jul 30, 2017 |
| CVE-2017-9071 | In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable on… | MEDIUM | 0.65% | May 18, 2017 |
| CVE-2017-9070 | In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to conn… | MEDIUM | 0.56% | May 18, 2017 |
| CVE-2017-9069 | In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess. | HIGH | 1.86% | May 18, 2017 |
| CVE-2017-9068 | In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by t… | MEDIUM | 0.69% | May 18, 2017 |
| CVE-2017-9067 | In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient valid… | HIGH | 0.82% | May 18, 2017 |
| CVE-2017-8115 | Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to ob… | MEDIUM | 2.68% | Apr 25, 2017 |
| CVE-2017-7324 | setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter. | CRITICAL | 2.16% | Mar 30, 2017 |
| CVE-2017-7323 | The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middl… | HIGH | 2.09% | Mar 30, 2017 |
| CVE-2017-7322 | The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows ma… | HIGH | 1.23% | Mar 30, 2017 |
| CVE-2017-7321 | setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the… | CRITICAL | 2.16% | Mar 30, 2017 |
| CVE-2017-7320 | setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to con… | MEDIUM | 0.87% | Mar 30, 2017 |
| CVE-2016-10039 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation… | HIGH | 1.76% | Dec 24, 2016 |
Showing 1 to 25 of 36 CVEs