CVE-2020-25911
- EPSS 0.96%
- Published 31.10.2021 19:15:09
- Last modified 21.11.2024 05:18:59
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
CVE-2019-1010123
- EPSS 0.21%
- Published 23.07.2019 13:15:12
- Last modified 21.11.2024 04:17:58
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb cla...
CVE-2018-20758
- EPSS 0.21%
- Published 06.02.2019 17:29:00
- Last modified 21.11.2024 04:02:06
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
CVE-2018-20757
- EPSS 0.24%
- Published 06.02.2019 17:29:00
- Last modified 21.11.2024 04:02:06
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
CVE-2018-20756
- EPSS 0.24%
- Published 06.02.2019 17:29:00
- Last modified 21.11.2024 04:02:06
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
CVE-2018-20755
- EPSS 0.24%
- Published 06.02.2019 17:29:00
- Last modified 21.11.2024 04:02:06
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
CVE-2018-17556
- EPSS 0.19%
- Published 26.09.2018 20:29:01
- Last modified 21.11.2024 03:54:35
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
CVE-2018-1000207
- EPSS 4.02%
- Published 13.07.2018 18:29:00
- Last modified 21.11.2024 03:39:56
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be explo...
CVE-2018-1000208
- EPSS 0.34%
- Published 13.07.2018 18:29:00
- Last modified 21.11.2024 03:39:56
MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable via web request via security/login processor. This vuln...
CVE-2018-10382
- EPSS 0.21%
- Published 01.06.2018 17:29:00
- Last modified 21.11.2024 03:41:18
MODX Revolution 2.6.3 has XSS.