📦

modxcms

Vendor: modxcms

Actively Exploited 0 CISA KEV List
PoC / Exploits 7 Code Available
Total RCEs 1 Remote Access
Total CVEs 251 Total Indexed
Avg. EPSS 1.72% Exploit Prob.
Latest CVE CVE-2010-1426 Apr 15

Security Vulnerability Index

Page 2 / 26
5.1 CVSS
CVE-2006-5730
Exploit Found

PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. NOTE: it is possible that this is a vulnerability in FCKeditor.

EPSS: 2.98%
5.8 CVSS
CVE-2006-1820
Exploit Found

Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.

EPSS: 2.09%
6.4 CVSS
CVE-2006-1821
Exploit Found

Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.

EPSS: 2.97%