VYPR

Evolution CMS

by Modx

Source repositories

CVEs (3)

  • CVE-2019-14518MedAug 15, 2019
    risk 0.35cvss 5.4epss 0.01

    Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.

  • CVE-2018-16638MedDec 28, 2018
    risk 0.28cvss 5.4epss 0.01

    Evolution CMS 1.4.x allows XSS via the manager/ search parameter.

  • CVE-2018-16637MedDec 28, 2018
    risk 0.28cvss 5.4epss 0.01

    Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.