Skip to main content

Vendor/product archive

intelliants / subrion CVEs

Beta · best-effort

25 CVEs tagged to intelliants / subrion3 Critical, 5 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2024-25400

Published Feb 27, 2024

Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43884

Published Sep 28, 2023

A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted p…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43830

Published Sep 27, 2023

A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43828

Published Sep 27, 2023

A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Tit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41948

Published Apr 29, 2022

A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22330

Published Aug 6, 2021

Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18155

Published Jul 14, 2021

SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-23761

Published Apr 9, 2021

Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20390

Published May 15, 2020

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20389

Published May 15, 2020

An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] p…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12469

Published Apr 29, 2020

admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12468

Published Apr 29, 2020

Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21037

Published Mar 17, 2020

Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17225

Published Oct 6, 2019

Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14840

Published Aug 2, 2018

uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15063

Published Oct 6, 2017

There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too lat…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10795

Published Jul 2, 2017

Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5543

Published Jan 20, 2017

includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login req…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9120

Published Dec 10, 2014

Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1