Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Modxcms

First CVE: Apr 18, 2006Active for: 20 yearsTotal CVEs: 18
28.9
VTI Score
Low

MODXCMS is a content management system with a modestly represented vulnerability footprint centered on its core MODXCMS product and related components such as Evolution and FileDownload. The vendor's disclosures cluster around web application input-handling weaknesses including cross-site scripting, SQL injection, path traversal, and cross-site request forgery, typical of server-side CMS platforms, and public exploit code has a notable tendency to become available for identified flaws. Current severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Modxcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2006
20 years ago
Most Recent CVE
Feb 2, 2011
5,651 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-0094MEDIUM
Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in
Jan 8, 20086.431NOYES
CVE-2008-5938MEDIUM
PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers t
Jan 22, 20096.827NOYES
CVE-2006-1821MEDIUM
Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id para
Apr 18, 20066.426NOYES
CVE-2006-1820MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be result
Apr 18, 20065.824NOYES
CVE-2010-3929HIGH
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
Feb 2, 20117.523NONO
CVE-2006-5730MEDIUM
PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbi
Nov 6, 20065.123NOYES
CVE-2008-7242MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3)
Sep 17, 20094.322NOYES
CVE-2010-1426HIGH
SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin.
Apr 15, 20107.521NONO
CVE-2008-5939MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the u
Jan 22, 20094.321NOYES
CVE-2008-7243MEDIUM
Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that m
Sep 17, 20096.820NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
83%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown18 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown18 (100.0%)
User Interaction
None0 (0.0%)
Unknown18 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown18 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
38.9% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Modxcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Modxcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Modxcms's Products

View all 2 CNAs →

Top CWEs