Show filters
62 Total Results
Displaying 1-10 of 62
Sort by:
Attacker Value
Unknown
CVE-2022-26149
Disclosure Date: February 26, 2022 (last updated October 07, 2023)
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
0
Attacker Value
Unknown
CVE-2020-25911
Disclosure Date: October 31, 2021 (last updated February 23, 2025)
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
0
Attacker Value
Unknown
CVE-2019-14518
Disclosure Date: August 15, 2019 (last updated November 08, 2023)
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.
0
Attacker Value
Unknown
CVE-2019-1010178
Disclosure Date: July 24, 2019 (last updated November 27, 2024)
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/components/fred/web/elfinder/connector.php. The attack vector is: Uploading a PHP file or change data in the database. The fixed version is: https://github.com/modxcms/fred/commit/139cefac83b2ead90da23187d92739dec79d3ccd and https://github.com/modxcms/fred/commit/01f0a3d1ae7f3970639c2a0db1887beba0065246.
0
Attacker Value
Unknown
CVE-2019-1010123
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web request via /assets/components/gallery/connector.php.
0
Attacker Value
Unknown
CVE-2018-20757
Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
0
Attacker Value
Unknown
CVE-2018-20758
Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
0
Attacker Value
Unknown
CVE-2018-20755
Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
0
Attacker Value
Unknown
CVE-2018-20756
Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
0
Attacker Value
Unknown
CVE-2018-16637
Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
0