Vulnerabilities > Modx > Modx Revolution > 1.9.1

DATE CVE VULNERABILITY TITLE RISK
2014-04-24 CVE-2014-2736 SQL Injection vulnerability in Modx Revolution
Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id parameter to manager/index.php.
network
low complexity
modx CWE-89
7.5
2014-03-01 CVE-2014-2080 Cross-Site Scripting vulnerability in Modx Revolution
Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.
network
modx CWE-79
4.3