VYPR
Medium severity6.1OSV Advisory· Published Feb 6, 2019· Updated Jun 17, 2026

CVE-2018-20756

CVE-2018-20756

Description

MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
modx/revolutionPackagist
< 2.7.1-pl2.7.1-pl

Affected products

4
  • Range: v2.0.1-pl, v2.0.3-pl, v2.0.4-pl, …
  • Modx/Revolution2 versions
    cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*range: <=2.7.0
    • cpe:2.3:a:modx:modx_revolution:2.7.0:pl:*:*:*:*:*:*
  • ghsa-coords
    Range: < 2.7.1-pl

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.