Known Vulnerabilities for products from Modxcms

Listed below are 18 of the newest known vulnerabilities associated with the vendor "Modxcms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2011-0741 json Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary... Not Provided 2011-02-02 2026-04-29
CVE-2010-3930 json Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via uns... Not Provided 2011-02-02 2026-04-29
CVE-2010-3929 json SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via... Not Provided 2011-02-02 2026-04-29
CVE-2010-1427 json Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers... Not Provided 2010-04-15 2026-04-29
CVE-2010-1426 json SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unkn... Not Provided 2010-04-15 2026-04-29
CVE-2008-7243 json Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijac... Not Provided 2009-09-17 2026-04-23
CVE-2008-7242 json Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitra... Not Provided 2009-09-17 2026-04-23
CVE-2008-5942 json Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web scr... Not Provided 2009-01-22 2026-04-23
CVE-2008-5941 json Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized... Not Provided 2009-01-22 2026-04-23
CVE-2008-5940 json SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attack... Not Provided 2009-01-22 2026-04-23
CVE-2008-5939 json Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbit... Not Provided 2009-01-22 2026-04-23
CVE-2008-5938 json PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when ... Not Provided 2009-01-22 2026-04-23
CVE-2008-0094 json Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include ... Not Provided 2008-01-08 2026-04-23
CVE-2007-5371 json Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrar... Not Provided 2007-10-11 2026-04-23
CVE-2007-0659 json download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files... Not Provided 2007-02-01 2026-04-23
CVE-2006-5730 json PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.... Not Provided 2006-11-06 2026-04-23
CVE-2006-1821 json Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot do... Not Provided 2006-04-18 2025-04-03
CVE-2006-1820 json Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or... Not Provided 2006-04-18 2025-04-03

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report