CVE-2014-2080

ModX Revolution <2.2.11 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.

Scores

EPSS 0.0032
EPSS Percentile 54.8%

Details

CWE
CWE-79
Status published
Products (27)
modx/modx_revolution < 2.2.10
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
... and 17 more
Published Mar 01, 2014
Tracked Since Feb 18, 2026