VYPR
Medium severity6.1OSV Advisory· Published Feb 6, 2019· Updated Jun 17, 2026

CVE-2018-20757

CVE-2018-20757

Description

MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
modx/revolutionPackagist
< 2.7.1-pl2.7.1-pl

Affected products

4
  • Range: v2.0.1-pl, v2.0.3-pl, v2.0.4-pl, …
  • ghsa-coords
    Range: < 2.7.1-pl
  • Modx/Revolution2 versions
    cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*range: <=2.7.0
    • cpe:2.3:a:modx:modx_revolution:2.7.0:pl:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.