Vulnerabilities > Modx > Modx Revolution > 2.5.5

DATE CVE VULNERABILITY TITLE RISK
2017-05-18 CVE-2017-9069 Unrestricted Upload of File with Dangerous Type vulnerability in Modx Revolution
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
network
low complexity
modx CWE-434
6.5
2017-05-18 CVE-2017-9068 Cross-site Scripting vulnerability in Modx Revolution
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
network
modx CWE-79
4.3