CVE-2014-2080
ModX Revolution <2.2.11 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.
References (5)
Scores
EPSS
0.0032
EPSS Percentile
54.8%
Details
CWE
CWE-79
Status
published
Products (27)
modx/modx_revolution
< 2.2.10
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
modx/modx_revolution
... and 17 more
Published
Mar 01, 2014
Tracked Since
Feb 18, 2026