Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-28010


A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.


Published

2025-03-13T16:15:27.690

Last Modified

2025-04-03T16:42:46.520

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application modx modx ≤ 3.1.0 Yes

References