Skip to content
Noroxi

modx records

44 published records for vendor modx.

All records

44 records
  • MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt

    HighCVSS 7.2No exploitEPSS 64%

    modx · modx revolutionJul 13, 2018

  • Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.

    CriticalCVSS 9.8No exploitEPSS 5%

    modx · fredJul 24, 2019

  • setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path

    CriticalCVSS 9.8No exploitEPSS 2%

    modx · modx revolutionMar 30, 2017

  • setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_k

    CriticalCVSS 9.8No exploitEPSS 2%

    modx · modx revolutionMar 30, 2017

  • A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an infor

    CriticalCVSS 9.1No exploitEPSS 2%

    modx · modx revolutionOct 31, 2021

  • CVE-2017-9069
    36Monitor

    In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .ht

    HighCVSS 8.8No exploitEPSS 2%

    modx · modx revolutionMay 18, 2017

  • MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in a

    HighCVSS 8.8No exploitEPSS 1%

    modx · revolutionJul 17, 2017

  • CVE-2017-7323
    33Monitor

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allo

    HighCVSS 8.1No exploitEPSS 2%

    modx · modx revolutionMar 30, 2017

  • CVE-2017-7322
    32Monitor

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL serve

    HighCVSS 8.1No exploitEPSS 1%

    modx · modx revolutionMar 30, 2017

  • MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, becau

    HighCVSS 7.2Proof of conceptEPSS 9%

    modx · revolutionFeb 26, 2022

  • MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result

    HighCVSS 7.5No exploitEPSS 2%

    modx · modx revolutionJul 13, 2018

  • Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    HighCVSS 7.3No exploitEPSS 2%

    modx · modx revolutionDec 24, 2016

  • Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    HighCVSS 7.3No exploitEPSS 2%

    modx · modx revolutionDec 24, 2016

  • Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/trav

    HighCVSS 7.3No exploitEPSS 2%

    modx · modx revolutionDec 24, 2016

  • CVE-2014-2736
    30Monitor

    Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1)

    HighCVSS 7.5No exploitEPSS 1%

    modx · modx revolutionApr 24, 2014

  • CVE-2014-2311
    30Monitor

    SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL comman

    HighCVSS 7.5No exploitEPSS 1%

    modx · modx revolutionMar 11, 2014

  • MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type.

    HighCVSS 7.5No exploitEPSS 1%

    modx · modx revolutionJul 23, 2019

  • CVE-2017-9067
    28Monitor

    In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to

    HighCVSS 7.0No exploitEPSS 1%

    modx · modx revolutionMay 18, 2017

  • CVE-2014-8773
    27Monitor

    MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitti

    MediumCVSS 6.8Proof of conceptEPSS 1%

    modx · modx revolutionDec 3, 2014

  • CVE-2015-6588
    24Monitor

    Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web s

    MediumCVSS 6.1No exploitEPSS 1%

    modx · modx revolutionAug 29, 2017

  • CVE-2017-7320
    24Monitor

    setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remo

    MediumCVSS 6.1No exploitEPSS 1%

    modx · modx revolutionMar 30, 2017

  • MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.

    MediumCVSS 6.1No exploitEPSS 1%

    modx · modx revolutionFeb 6, 2019

  • MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.

    MediumCVSS 6.1No exploitEPSS 1%

    modx · modx revolutionFeb 6, 2019

  • MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Qui

    MediumCVSS 6.1No exploitEPSS 1%

    modx · modx revolutionFeb 6, 2019

  • CVE-2017-9068
    24Monitor

    In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, a

    MediumCVSS 6.1No exploitEPSS 1%

    modx · modx revolutionMay 18, 2017