Show filters
62 Total Results
Displaying 1-10 of 62
Sort by:
Attacker Value
Unknown

CVE-2022-26149

Disclosure Date: February 26, 2022 (last updated October 07, 2023)
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
Attacker Value
Unknown

CVE-2020-25911

Disclosure Date: October 31, 2021 (last updated February 23, 2025)
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
Attacker Value
Unknown

CVE-2019-14518

Disclosure Date: August 15, 2019 (last updated November 08, 2023)
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.
0
Attacker Value
Unknown

CVE-2019-1010178

Disclosure Date: July 24, 2019 (last updated November 27, 2024)
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/components/fred/web/elfinder/connector.php. The attack vector is: Uploading a PHP file or change data in the database. The fixed version is: https://github.com/modxcms/fred/commit/139cefac83b2ead90da23187d92739dec79d3ccd and https://github.com/modxcms/fred/commit/01f0a3d1ae7f3970639c2a0db1887beba0065246.
Attacker Value
Unknown

CVE-2019-1010123

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web request via /assets/components/gallery/connector.php.
0
Attacker Value
Unknown

CVE-2018-20757

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
0
Attacker Value
Unknown

CVE-2018-20758

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
Attacker Value
Unknown

CVE-2018-20755

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
0
Attacker Value
Unknown

CVE-2018-20756

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
0
Attacker Value
Unknown

CVE-2018-16637

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
0