VendorsMODXevolution_cmsall versions
Vulnerabilities

MODX Evolution CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2019-14518
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.
Published 2019-08-15 · Modified
5.4EPSS 0.012
CVE-2018-16638
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
Published 2018-12-28 · Modified
5.4EPSS 0.006
CVE-2018-16637
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
Published 2018-12-28 · Modified
5.4EPSS 0.006