Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
modx vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2018-17556
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
Modx Modx Revolution 2.6.5
4.3
CVSSv2
CVE-2017-11744
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
Modx Modx Revolution 2.5.7
3.5
CVSSv2
CVE-2018-10382
MODX Revolution 2.6.3 has XSS.
Modx Modx Revolution 2.6.3
6.4
CVSSv2
CVE-2020-25911
A XML External Entity (XXE) vulnerability exists in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
Modx Modx Revolution 2.7.3
4.3
CVSSv2
CVE-2014-8992
Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl allows remote malicious users to inject arbitrary web script or HTML via the callback parameter.
Modx Modx Revolution 2.3.2
5
CVSSv2
CVE-2017-8115
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote malicious users to obtain system directory information.
Modx Modx Revolution 2.5.7
4.4
CVSSv2
CVE-2017-9067
In MODX Revolution prior to 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
Modx Modx Revolution 2.5.6
Php Php 5.3.3
6.5
CVSSv2
CVE-2022-26149
MODX Revolution up to and including 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
Modx Revolution
3.5
CVSSv2
CVE-2018-16637
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
Modx Evolution Cms
3.5
CVSSv2
CVE-2018-16638
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
Modx Evolution Cms
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »