modx/revolution

composervv3.2.0-pl

MODX Revolution is a Content Management System

License GPL-2.0+31 versions3 maintainers29 deps
modxcms/revolution
36
/ 100
Health
do not use

modx/revolution has critical vulnerabilities — do not use

Update to >= 2.7.1-pl to fix known vulnerabilities

  • Low health score (36/100)
  • 5 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
20/25
maintenance
0/20
popularity
0/25
security
12/15
maturity
4/15
community
Vulnerabilities
14
1 critical5 high7 medium1 low
Advisories (14)
SeverityIDSummaryFixed in
highCVE-2017-9069MODX Revolution allows overwriting .htaccess2.5.7
mediumCVE-2017-9070MODX Revolution cross-site scripting vulnerability2.5.7
highCVE-2017-9067MODX Revolution Directory Traversal Vulnerability2.5.7
mediumCVE-2018-20756MODX Revolution allows XSS via document resources2.7.1-pl
mediumCVE-2018-20757MODX Revolution allows XSS through extended user fields2.7.1-pl
lowCVE-2025-28010MODX allows cross-site scripting (XSS) via an SVG file
highCVE-2022-26149Unrestricted Upload of File with Dangerous Type in MODX Revolution
highCVE-2018-1000207MODX Revolution Incorrect Access Control vulnerability2.7.0
mediumCVE-2017-9071MODX Revolution XSS via HTTP Host header2.5.7
highCVE-2017-1000067MODX Revolution blind SQL injection2.6.0
mediumCVE-2018-20755MODX Revolution vulnerable to XSS attack through its User Photo field2.7.1-pl
criticalBIT-modx-2020-25911XML External Entity vulnerability in MODX CMS2.8.0
mediumCVE-2017-9068MODX Revolution Reflected XSS2.5.7
mediumCVE-2018-20758MODX vulnerability allows for XSS via user settings parameters2.7.1-pl

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/composer/modx/revolution

Last updated · 2026-02-17T16:26:46+00:00