High severity7.2NVD Advisory· Published Feb 26, 2022· Updated Jun 17, 2026
CVE-2022-26149
CVE-2022-26149
Description
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
modx/revolutionPackagist | <= 2.8.3-pl | — |
Affected products
3cpe:2.3:a:modx:revolution:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:modx:revolution:*:*:*:*:*:*:*:*range: <=2.8.3
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/sartlabs/0days/blob/main/Modx/Exploit.txtnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-j8jp-9x42-4pj5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-26149ghsaADVISORY
- packetstormsecurity.com/files/171488/MODX-Revolution-2.8.3-pl-Remote-Code-Execution.htmlnvdWEB
News mentions
0No linked articles in our index yet.