Description MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description. Remediation References CVE-2018-20758 Related Vulnerabilities PHP Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2010-2191) Oracle Database Server CVE-2023-22073 Vulnerability (CVE-2023-22073) WordPress Plugin Ocean Extra Security Bypass (1.5.8) Oracle JRE CVE-2018-2627 Vulnerability (CVE-2018-2627) WordPress Plugin Gallery by BestWebSoft Cross-Site Scripting (4.2.1) Severity Medium Classification CVE-2018-20758 CWE-707 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities