MODXCMS is a content management system with a modestly represented vulnerability footprint centered on its core MODXCMS product and related components such as Evolution and FileDownload. The vendor's disclosures cluster around web application input-handling weaknesses including cross-site scripting, SQL injection, path traversal, and cross-site request forgery, typical of server-side CMS platforms, and public exploit code has a notable tendency to become available for identified flaws. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Modxcms over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0094MEDIUM Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in | Jan 8, 2008 | 6.4 | 31 | NO | YES |
CVE-2008-5938MEDIUM PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers t | Jan 22, 2009 | 6.8 | 27 | NO | YES |
CVE-2006-1821MEDIUM Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id para | Apr 18, 2006 | 6.4 | 26 | NO | YES |
CVE-2006-1820MEDIUM Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be result | Apr 18, 2006 | 5.8 | 24 | NO | YES |
CVE-2010-3929HIGH SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch. | Feb 2, 2011 | 7.5 | 23 | NO | NO |
CVE-2006-5730MEDIUM PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbi | Nov 6, 2006 | 5.1 | 23 | NO | YES |
CVE-2008-7242MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) | Sep 17, 2009 | 4.3 | 22 | NO | YES |
CVE-2010-1426HIGH SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin. | Apr 15, 2010 | 7.5 | 21 | NO | NO |
CVE-2008-5939MEDIUM Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the u | Jan 22, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-7243MEDIUM Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that m | Sep 17, 2009 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Modxcms.
Media articles that mention a CVE ID that affects a product developed by Modxcms — matched by CVE ID, not by vendor name.