CVE Tools

Modx

31 CVEs tracked since 2011. Since Oct 2011, none of them reached CISA KEV.

Modx CVEs per month

Oct 2011 to Feb 2019. Point at a month, or focus the strip and use the arrow keys.
Modx CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2011-1010
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08null or fewer
2012-09null or fewer
2012-1010
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-0210
2014-0310
2014-0410
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-1110
2014-1240
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-1230
2017-01null or fewer
2017-02null or fewer
2017-0350
2017-04null or fewer
2017-0550
2017-06null or fewer
2017-0720
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-1220
2019-01null or fewer
2019-0240

Products

The products that kept showing up in Modx's monthly top three, with their CVEs summed over those months.

  1. Modx Revolution2711 months
  2. Evolution CMS21 month
  3. Revolution22 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Modx.

  1. CVE-2025-28010A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profi...5.4
  2. CVE-2022-26149MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an...7.2
  3. CVE-2020-25911A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).9.1
  4. CVE-2019-14518Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.5.4
  5. CVE-2019-1010178Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/components/fred/web/elfinder/connector.php. The...9.8
  6. CVE-2019-1010123MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering ...7.5
  7. CVE-2018-20758MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.5.4
  8. CVE-2018-20756MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.6.1
  9. CVE-2018-20757MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.6.1
  10. CVE-2018-20755MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.6.1
  11. CVE-2018-16637Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.5.4
  12. CVE-2018-16638Evolution CMS 1.4.x allows XSS via the manager/ search parameter.5.4
  13. CVE-2018-17556MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.5.4
  14. CVE-2018-1000207MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a...7.2
  15. CVE-2018-1000208MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable vi...7.5

The record

Peak rank
#34 in Dec 2014
Busiest month shown
Mar 2017, 5 CVEs
Months with a KEV entry
0 since Oct 2011
Monthly snapshots
13 since 2011
Modx's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store