threat
engine
.sh
Back
·
··:··
Home
/
Product
/
intelliants subrion cms
Product
intelliants subrion cms
38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-70958
all versions
Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to
6.1
MEDIUM
CVE-2025-56556
all versions
An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run S
3.8
LOW
CVE-2024-25399
all versions
Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
6.1
MEDIUM
CVE-2023-43875
all versions
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbi
6.1
MEDIUM
CVE-2022-43121
all versions
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute
6.1
MEDIUM
CVE-2022-43120
all versions
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers t
6.1
MEDIUM
CVE-2022-37059
all versions
Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field
4.8
MEDIUM
CVE-2021-41502
all versions
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute maliciou
5.4
MEDIUM
CVE-2021-43464
all versions
A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the informat
8.8
HIGH
CVE-2020-18326
all versions
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, w
8.8
HIGH
CVE-2020-18325
all versions
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
6.1
MEDIUM
CVE-2020-18324
all versions
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
6.1
MEDIUM
CVE-2021-43724
<= 4.2.1
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Accoun
4.8
MEDIUM
CVE-2021-41947
all versions
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
7.2
HIGH
CVE-2020-22392
all versions
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
5.4
MEDIUM
CVE-2020-35437
all versions
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/pr
6.1
MEDIUM
CVE-2019-7357
all versions
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
8.8
HIGH
CVE-2019-11406
all versions
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
6.1
MEDIUM
CVE-2017-18366
all versions
Subrion CMS 4.1.5 has CSRF in blog/delete/.
8.8
HIGH
CVE-2018-16631
all versions
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
5.4
MEDIUM
CVE-2018-16629
all versions
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
4.8
MEDIUM
CVE-2018-19422
all versions
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .h
7.2
HIGH
CVE-2018-14836
all versions
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access
6.5
MEDIUM
CVE-2018-14835
all versions
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple
5.4
MEDIUM
CVE-2017-11445
<= 4.1.4
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
9.8
CRITICAL
CVE-2017-11444
<= 4.1.4
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
9.8
CRITICAL
CVE-2017-6069
all versions
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
8.8
HIGH
CVE-2017-6068
all versions
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content
8.8
HIGH
CVE-2017-6066
all versions
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally inser
8.8
HIGH
CVE-2017-6013
all versions
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
9.8
CRITICAL
CVE-2017-6002
all versions
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that ent
8.8
HIGH
CVE-2015-4129
<= 3.3.2
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via mo
CVE-2012-5452
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or
CVE-2012-4773
<= 2.2.2
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authen
CVE-2012-4772
<= 2.2.2
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via
CVE-2012-4771
<= 2.2.2
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web scr
CVE-2011-5212
all versions
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via
CVE-2011-5211
all versions
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web s
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin