Vulnerabilities > Modx > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-08-15 CVE-2019-14518 Cross-site Scripting vulnerability in Modx Evolution CMS 2.0.0
Evolution CMS 2.0.x allows XSS via a description and new category location in a template.
network
low complexity
modx CWE-79
5.4
2019-02-06 CVE-2018-20758 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
network
low complexity
modx CWE-79
5.4
2019-02-06 CVE-2018-20757 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
network
low complexity
modx CWE-79
6.1
2019-02-06 CVE-2018-20756 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
network
low complexity
modx CWE-79
6.1
2019-02-06 CVE-2018-20755 Cross-site Scripting vulnerability in Modx Revolution
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
network
low complexity
modx CWE-79
6.1
2018-12-28 CVE-2018-16638 Cross-site Scripting vulnerability in Modx Evolution CMS
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
network
low complexity
modx CWE-79
5.4
2018-12-28 CVE-2018-16637 Cross-site Scripting vulnerability in Modx Evolution CMS
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
network
low complexity
modx CWE-79
5.4
2018-09-26 CVE-2018-17556 Cross-site Scripting vulnerability in Modx Revolution 2.6.5
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
network
low complexity
modx CWE-79
5.4
2018-06-01 CVE-2018-10382 Cross-site Scripting vulnerability in Modx Revolution 2.6.3
MODX Revolution 2.6.3 has XSS.
network
low complexity
modx CWE-79
5.4
2017-11-17 CVE-2017-1000223 Cross-site Scripting vulnerability in Modx Revolution
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier.
network
low complexity
modx CWE-79
5.4