MODX Revolution is a Content Management System
98%
Total Score
95
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-28010 modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.1.0. | 0.0.0 - 3.1.0 | Medium |
CVE-2017-1000067 modx/revolution is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 2.0.0 - 2.5.6. | 2.0.0 - 2.5.6 | High |
CVE-2018-1000207 modx/revolution is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.0.0 - 2.6.4. | 0.0.0 - 2.6.4 | High |
CVE-2022-26149 modx/revolution is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 2.8.3-pl. | 0.0.0 - 2.8.3-pl | High |
CVE-2020-25911 modx/revolution is vulnerable to Improper Restriction of XML External Entity Reference in versions 0.0.0 - 2.8.0. | 0.0.0 - 2.8.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
xpdo/xpdo Version ~3.1.0 | — | — |
pimple/pimple Version ^3.0 | — | — |
smarty/smarty Version ^4.0 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant