modx/revolution
composervv3.2.0-plMODX Revolution is a Content Management System
License GPL-2.0+31 versions3 maintainers29 deps
modxcms/revolution36
/ 100
Health
do not use
modx/revolution has critical vulnerabilities — do not use
Update to >= 2.7.1-pl to fix known vulnerabilities
- Low health score (36/100)
- 5 high severity vulnerabilities
- 1 critical vulnerabilities
Health breakdown0 – 100
20/25
maintenance
0/20
popularity
0/25
security
12/15
maturity
4/15
community
Vulnerabilities
14
1 critical5 high7 medium1 low
Advisories (14)
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2017-9069 | MODX Revolution allows overwriting .htaccess | 2.5.7 |
| medium | CVE-2017-9070 | MODX Revolution cross-site scripting vulnerability | 2.5.7 |
| high | CVE-2017-9067 | MODX Revolution Directory Traversal Vulnerability | 2.5.7 |
| medium | CVE-2018-20756 | MODX Revolution allows XSS via document resources | 2.7.1-pl |
| medium | CVE-2018-20757 | MODX Revolution allows XSS through extended user fields | 2.7.1-pl |
| low | CVE-2025-28010 | MODX allows cross-site scripting (XSS) via an SVG file | — |
| high | CVE-2022-26149 | Unrestricted Upload of File with Dangerous Type in MODX Revolution | — |
| high | CVE-2018-1000207 | MODX Revolution Incorrect Access Control vulnerability | 2.7.0 |
| medium | CVE-2017-9071 | MODX Revolution XSS via HTTP Host header | 2.5.7 |
| high | CVE-2017-1000067 | MODX Revolution blind SQL injection | 2.6.0 |
| medium | CVE-2018-20755 | MODX Revolution vulnerable to XSS attack through its User Photo field | 2.7.1-pl |
| critical | BIT-modx-2020-25911 | XML External Entity vulnerability in MODX CMS | 2.8.0 |
| medium | CVE-2017-9068 | MODX Revolution Reflected XSS | 2.5.7 |
| medium | CVE-2018-20758 | MODX vulnerability allows for XSS via user settings parameters | 2.7.1-pl |
Health History
Dependency Tree
License Audit
Dependencies (29)
phpxpdo/xpdoleague/flysystemleague/flysystem-aws-s3-v3league/flysystem-ftpphpmailer/phpmailersmarty/smartyjames-heinrich/phpthumberusev/parsedowninlinestyle/inlinestylesimplepie/simplepiepimple/pimplepsr/http-clientpsr/http-messagepsr/http-factoryguzzlehttp/guzzleguzzlehttp/psr7ext-curlext-domext-gdext-zlibext-jsonext-simplexmlext-pdoext-xmlext-zipext-xmlwriterext-fileinfosymfony/polyfill-php82
API access
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/composer/modx/revolutionLast updated · 2026-02-17T16:26:46+00:00