Showing 14 vulnerabilities on this page for modx/revolution

Signals CISA KEV Ransomware Nuclei
Packagist vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

MODX allows cross-site scripting (XSS) via an SVG file

A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

CWE-79Mar 13, 2025
CVSS-v4.0EPSS0.25%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unrestricted Upload of File with Dangerous Type in MODX Revolution

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.

CWE-434Feb 26, 2022
CVSS7.2v3.1EPSS9.31%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

XML External Entity vulnerability in MODX CMS

A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

CWE-611Oct 31, 2021
CVSS9.1v3.1EPSS2.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution vulnerable to XSS attack through its User Photo field

MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.

CWE-79Feb 6, 2019
CVSS6.1v3.0EPSS0.861%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX vulnerability allows for XSS via user settings parameters

MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.

CWE-79Feb 6, 2019
CVSS5.4v3.1EPSS0.609%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution allows XSS through extended user fields

MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.

CWE-79Feb 6, 2019
CVSS6.1v3.0EPSS0.861%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution allows XSS via document resources

MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.

CWE-79Feb 6, 2019
CVSS6.1v3.0EPSS0.861%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution Incorrect Access Control vulnerability

MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed in commit 06bc94257408f6a575de20ddb955aca505ef6e68.

CWE-732Jul 13, 2018
CVSS7.2v3.0EPSS64.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution blind SQL injection

MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.

CWE-89Jul 13, 2017
CVSS8.8v3.0EPSS1.11%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution cross-site scripting vulnerability

In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.

CWE-79May 18, 2017
CVSS5.4v3.0EPSS0.563%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution Reflected XSS

In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.

CWE-79May 18, 2017
CVSS6.1v3.0EPSS0.686%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution allows overwriting .htaccess

In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.

CWE-434May 18, 2017
CVSS8.8v3.0EPSS1.87%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution XSS via HTTP Host header

In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.

CWE-79May 18, 2017
CVSS4.7v3.0EPSS0.649%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MODX Revolution Directory Traversal Vulnerability

In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.

CWE-22May 18, 2017
CVSS7.0v3.0EPSS0.82%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX