Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Evolution Cms MEDIUM 5.4
CVE-2019-14518

Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent wit…

No fix yet
Fix from $1,600 2019-08-15
Fred CRITICAL 9.8
CVE-2019-1010178

Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets…

No fix yet
Fix from $2,300 2019-07-24
Modx Revolution MEDIUM 5.4
CVE-2018-17556

MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.

Mitigation only
Fix from $1,600 2018-09-26
Revolution HIGH 8.8
CVE-2017-1000067

MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authentica…

Mitigation only
Fix from $1,950 2017-07-17
Modx Revolution MEDIUM 5.0
CVE-2014-8775

MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote …

No fix yet
Fix from $1,600 2014-12-03
Modx Revolution MEDIUM 6.8
CVE-2014-8773

MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CS…

No fix yet
Fix from $1,600 2014-12-03
Modx Revolution HIGH 7.5
CVE-2014-2311

SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via un…

Mitigation only
Fix from $1,950 2014-03-11