Vulnerabilities > Modx > Modx Revolution > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-10-31 CVE-2020-25911 XXE vulnerability in Modx Revolution 2.7.3
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
network
low complexity
modx CWE-611
critical
9.1
2017-03-30 CVE-2017-7321 Code Injection vulnerability in Modx Revolution
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.
network
low complexity
modx CWE-94
critical
9.8
2017-03-30 CVE-2017-7324 Code Injection vulnerability in Modx Revolution
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter.
network
low complexity
modx CWE-94
critical
9.8