Modxcms
15 CVEs tracked since 2006. Since Apr 2006, none of them reached CISA KEV.
Modxcms CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2006-04 | 2 | 0 |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | null or fewer | |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | null or fewer | |
| 2007-10 | null or fewer | |
| 2007-11 | null or fewer | |
| 2007-12 | null or fewer | |
| 2008-01 | 1 | 0 |
| 2008-02 | null or fewer | |
| 2008-03 | null or fewer | |
| 2008-04 | null or fewer | |
| 2008-05 | null or fewer | |
| 2008-06 | null or fewer | |
| 2008-07 | null or fewer | |
| 2008-08 | null or fewer | |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | null or fewer | |
| 2008-12 | null or fewer | |
| 2009-01 | 5 | 0 |
| 2009-02 | null or fewer | |
| 2009-03 | null or fewer | |
| 2009-04 | null or fewer | |
| 2009-05 | null or fewer | |
| 2009-06 | null or fewer | |
| 2009-07 | null or fewer | |
| 2009-08 | null or fewer | |
| 2009-09 | 2 | 0 |
| 2009-10 | null or fewer | |
| 2009-11 | null or fewer | |
| 2009-12 | null or fewer | |
| 2010-01 | null or fewer | |
| 2010-02 | null or fewer | |
| 2010-03 | null or fewer | |
| 2010-04 | 2 | 0 |
| 2010-05 | null or fewer | |
| 2010-06 | null or fewer | |
| 2010-07 | null or fewer | |
| 2010-08 | null or fewer | |
| 2010-09 | null or fewer | |
| 2010-10 | null or fewer | |
| 2010-11 | null or fewer | |
| 2010-12 | null or fewer | |
| 2011-01 | null or fewer | |
| 2011-02 | 3 | 0 |
Products
The products that kept showing up in Modxcms's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Modxcms.
- CVE-2010-3930Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than C...5.0
- CVE-2010-3929SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.7.5
- CVE-2011-0741Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.4.3
- CVE-2010-1426SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin.7.5
- CVE-2010-1427Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to A...4.3
- CVE-2008-7243Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords v...6.8
- CVE-2008-7242Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, a...4.3
- CVE-2008-5940SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the searchid parameter. NOTE:...6.8
- CVE-2008-5939Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the username field, po...4.3
- CVE-2008-5942Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the preserveUrls function and (2)...4.3
- CVE-2008-5941Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.6.0
- CVE-2008-5938PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitra...6.8
- CVE-2008-0094Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language ...6.4
- CVE-2007-5371Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrary SQL commands via the (1) documentDirty or (2) modVariables parameter.6.8
- CVE-2007-0659download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database crede...7.5
The record
- Peak rank
- #15 in Jan 2009
- Busiest month shown
- Jan 2009, 5 CVEs
- Months with a KEV entry
- 0 since Apr 2006
- Monthly snapshots
- 6 since 2006