CVE-2020-25911: Modx Revolution

Critical severity, CVSS 9.1. EPSS: 2.4% chance of exploitation in the next 30 days.

A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

Affected products

  • Modx Modx Revolution: version 2.7.3 only

Published 2021-10-31. Last modified 2026-06-17.