Home/Product/intelliants subrion cms
Product

intelliants subrion cms

38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-70958
all versions
Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to
6.1MEDIUM
CVE-2025-56556
all versions
An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run S
3.8LOW
CVE-2024-25399
all versions
Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
6.1MEDIUM
CVE-2023-43875
all versions
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbi
6.1MEDIUM
CVE-2022-43121
all versions
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute
6.1MEDIUM
CVE-2022-43120
all versions
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers t
6.1MEDIUM
CVE-2022-37059
all versions
Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field
4.8MEDIUM
CVE-2021-41502
all versions
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute maliciou
5.4MEDIUM
CVE-2021-43464
all versions
A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the informat
8.8HIGH
CVE-2020-18326
all versions
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, w
8.8HIGH
CVE-2020-18325
all versions
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
6.1MEDIUM
CVE-2020-18324
all versions
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
6.1MEDIUM
CVE-2021-43724
<= 4.2.1
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Accoun
4.8MEDIUM
CVE-2021-41947
all versions
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
7.2HIGH
CVE-2020-22392
all versions
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
5.4MEDIUM
CVE-2020-35437
all versions
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/pr
6.1MEDIUM
CVE-2019-7357
all versions
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
8.8HIGH
CVE-2019-11406
all versions
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
6.1MEDIUM
CVE-2017-18366
all versions
Subrion CMS 4.1.5 has CSRF in blog/delete/.
8.8HIGH
CVE-2018-16631
all versions
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
5.4MEDIUM
CVE-2018-16629
all versions
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
4.8MEDIUM
CVE-2018-19422
all versions
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .h
7.2HIGH
CVE-2018-14836
all versions
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access
6.5MEDIUM
CVE-2018-14835
all versions
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple
5.4MEDIUM
CVE-2017-11445
<= 4.1.4
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
9.8CRITICAL
CVE-2017-11444
<= 4.1.4
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
9.8CRITICAL
CVE-2017-6069
all versions
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
8.8HIGH
CVE-2017-6068
all versions
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content
8.8HIGH
CVE-2017-6066
all versions
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally inser
8.8HIGH
CVE-2017-6013
all versions
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
9.8CRITICAL
CVE-2017-6002
all versions
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that ent
8.8HIGH
CVE-2015-4129
<= 3.3.2
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via mo
CVE-2012-5452
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or
CVE-2012-4773
<= 2.2.2
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authen
CVE-2012-4772
<= 2.2.2
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via
CVE-2012-4771
<= 2.2.2
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web scr
CVE-2011-5212
all versions
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via
CVE-2011-5211
all versions
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web s
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin