Medium severity6.1OSV Advisory· Published Feb 6, 2019· Updated Jun 17, 2026
CVE-2018-20756
CVE-2018-20756
Description
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
modx/revolutionPackagist | < 2.7.1-pl | 2.7.1-pl |
Affected products
4- Range: v2.0.1-pl, v2.0.3-pl, v2.0.4-pl, …
cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*range: <=2.7.0
- cpe:2.3:a:modx:modx_revolution:2.7.0:pl:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- github.com/modxcms/revolution/issues/14105nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-fpxg-5x79-43rmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-20756ghsaADVISORY
- github.com/modxcms/revolution/commit/71f894ee55dc4eed10538979761d6c94e8cd1078ghsaWEB
- github.com/modxcms/revolution/pull/14335ghsaWEB
News mentions
0No linked articles in our index yet.