VYPR
Unrated severityNVD Advisory· Published Mar 1, 2014· Updated Apr 29, 2026

CVE-2014-2080

CVE-2014-2080

Description

Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.

Affected products

26
  • Modx/Revolution26 versions
    cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*+ 25 more
    • cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*range: <=2.2.10
    • cpe:2.3:a:modx:modx_revolution:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:modx:modx_revolution:2.2.9:*:*:*:*:*:*:*

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

5

News mentions

0

No linked articles in our index yet.