CVE-2017-9068: Modx Revolution
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
Affected products
- Modx Modx Revolution: up to and including 2.5.6
Published 2017-05-18. Last modified 2026-06-17.