Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2019-14518 Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent wit… Evolution Cms No fix yet Fix from $1,6002019-08-15 CRITICAL 9.8 CVE-2019-1010178 Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets… Fred No fix yet Fix from $2,3002019-07-24 MEDIUM 5.4 CVE-2018-17556 MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action. Modx Revolution Mitigation only Fix from $1,6002018-09-26 HIGH 8.8 CVE-2017-1000067 MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authentica… Revolution Mitigation only Fix from $1,9502017-07-17 MEDIUM 5.0 CVE-2014-8775 MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote … Modx Revolution No fix yet Fix from $1,6002014-12-03 MEDIUM 6.8 CVE-2014-8773 MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CS… Modx Revolution No fix yet Fix from $1,6002014-12-03 HIGH 7.5 CVE-2014-2311 SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via un… Modx Revolution Mitigation only Fix from $1,9502014-03-11