Vulnerabilities > Modx > Modx Revolution

DATE CVE VULNERABILITY TITLE RISK
2021-10-31 CVE-2020-25911 XXE vulnerability in Modx Revolution 2.7.3
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
network
low complexity
modx CWE-611
6.4
2019-07-23 CVE-2019-1010123 Unrestricted Upload of File with Dangerous Type vulnerability in Modx Revolution
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type.
network
low complexity
modx CWE-434
5.0
2019-02-06 CVE-2018-20758 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
network
modx CWE-79
3.5
2019-02-06 CVE-2018-20757 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
network
modx CWE-79
4.3
2019-02-06 CVE-2018-20756 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
network
modx CWE-79
4.3
2019-02-06 CVE-2018-20755 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
network
modx CWE-79
4.3
2018-09-26 CVE-2018-17556 Cross-site Scripting vulnerability in Modx Revolution 2.6.5
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
network
modx CWE-79
3.5
2018-07-13 CVE-2018-1000208 Path Traversal vulnerability in Modx Revolution
MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files.
network
low complexity
modx CWE-22
6.4
2018-07-13 CVE-2018-1000207 Incorrect Permission Assignment for Critical Resource vulnerability in Modx Revolution
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content.
network
low complexity
modx CWE-732
6.5
2018-06-01 CVE-2018-10382 Cross-site Scripting vulnerability in Modx Revolution 2.6.3
MODX Revolution 2.6.3 has XSS.
network
modx CWE-79
3.5