Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-28010 A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG fil… Modx after 3.1.0 Fix from $1,6002025-03-13 HIGH 7.2 CVE-2022-26149EPSS 9% MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Up… Revolution after 2.8.3 Fix from $1,9502022-02-26 CRITICAL 9.1 CVE-2020-25911 A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information di… Modx Revolution Patch available Fix from $2,3002021-10-31 MEDIUM 5.4 CVE-2019-14518 Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent wit… Evolution Cms No fix yet Fix from $1,6002019-08-15 CRITICAL 9.8 CVE-2019-1010178 Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets… Fred No fix yet Fix from $2,3002019-07-24 HIGH 7.5 CVE-2019-1010123 MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a fi… Modx Revolution after 2.6.4 Fix from $1,9502019-07-23 MEDIUM 6.1 CVE-2018-20755 MODX Revolution through v2.7.0-pl allows XSS via the User Photo field. Modx Revolution after 2.7.0 Fix from $1,6002019-02-06 MEDIUM 6.1 CVE-2018-20756 MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit a… Modx Revolution after 2.7.0 Fix from $1,6002019-02-06 MEDIUM 6.1 CVE-2018-20757 MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name. Modx Revolution after 2.7.0 Fix from $1,6002019-02-06 MEDIUM 5.4 CVE-2018-20758 MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description. Modx Revolution after 2.7.0 Fix from $1,6002019-02-06 MEDIUM 5.4 CVE-2018-16637 Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. Evolution Cms after 1.4.7 Fix from $1,6002018-12-28 MEDIUM 5.4 CVE-2018-16638 Evolution CMS 1.4.x allows XSS via the manager/ search parameter. Evolution Cms after 1.4.7 Fix from $1,6002018-12-28 MEDIUM 5.4 CVE-2018-17556 MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action. Modx Revolution Mitigation only Fix from $1,6002018-09-26 HIGH 7.5 CVE-2018-1000208 MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remov… Modx Revolution after 2.6.4 Fix from $1,9502018-07-13 HIGH 7.2 CVE-2018-1000207EPSS 64% MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb clas… Modx Revolution after 2.6.4 Fix from $1,9502018-07-13 MEDIUM 5.4 CVE-2018-10382 MODX Revolution 2.6.3 has XSS. Modx Revolution Patch available Fix from $1,6002018-06-01 MEDIUM 5.4 CVE-2017-1000223 A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with… Modx Revolution after 2.5.6 Fix from $1,6002017-11-17 MEDIUM 6.1 CVE-2015-6588 Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or … Modx Revolution after 1.9.0 Fix from $1,6002017-08-29 MEDIUM 6.1 CVE-2017-11744 In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors… Modx Revolution Patch available Fix from $1,6002017-07-30 HIGH 8.8 CVE-2017-1000067 MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authentica… Revolution Mitigation only Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-9069 In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess. Modx Revolution after 2.5.6 Fix from $1,9502017-05-18 MEDIUM 6.1 CVE-2017-9068 In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonst… Modx Revolution after 2.5.6 Fix from $1,6002017-05-18 MEDIUM 5.4 CVE-2017-9070 In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle paramet… Modx Revolution after 2.5.6 Fix from $1,6002017-05-18 MEDIUM 5.3 CVE-2017-8115 Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attac… Modx Revolution Patch available Fix from $1,6002017-04-25 CRITICAL 9.8 CVE-2017-7321 setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parame… Modx Revolution after 2.5.4 Fix from $2,3002017-03-30 CRITICAL 9.8 CVE-2017-7324 setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path paramete… Modx Revolution after 2.5.4 Fix from $2,3002017-03-30 HIGH 8.1 CVE-2017-7322 The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which… Modx Revolution after 2.5.4 Fix from $1,9502017-03-30 HIGH 8.1 CVE-2017-7323 The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in… Modx Revolution after 2.5.4 Fix from $1,9502017-03-30 MEDIUM 6.1 CVE-2017-7320 setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attack… Modx Revolution after 2.5.4 Fix from $1,6002017-03-30 HIGH 7.3 CVE-2016-10037 Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/man… Modx Revolution 2.5.2+ Fix from $1,9502016-12-24