VYPR

CMS

by Subrion

Source repositories

CVEs (20)

  • CVE-2017-11444CriJul 19, 2017
    risk 0.65cvss 9.8epss 0.13

    Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.

  • CVE-2017-11445CriJul 19, 2017
    risk 0.64cvss 9.8epss 0.01

    Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.

  • CVE-2017-6013CriMar 27, 2017
    risk 0.64cvss 9.8epss 0.02

    Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.

  • CVE-2019-7357HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.

  • CVE-2017-6069HigMar 27, 2017
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.

  • CVE-2017-6066HigMar 27, 2017
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.

  • CVE-2017-6002HigMar 27, 2017
    risk 0.57cvss 8.8epss 0.00

    Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.

  • CVE-2021-41947HigOct 8, 2021
    risk 0.47cvss 7.2epss 0.01

    A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

  • CVE-2020-35437MedDec 26, 2020
    risk 0.43cvss 6.1epss 0.03

    Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.

  • CVE-2018-14836MedAug 2, 2018
    risk 0.42cvss 6.5epss 0.01

    Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.

  • CVE-2023-43875MedOct 19, 2023
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.

  • CVE-2020-22392MedAug 5, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.

  • CVE-2019-7356MedNov 4, 2020
    risk 0.35cvss 5.4epss 0.01

    Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.

  • CVE-2022-37059MedAug 29, 2022
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field

  • CVE-2018-14835MedAug 2, 2018
    risk 0.28cvss 5.4epss 0.01

    Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.

  • CVE-2025-56556LowSep 11, 2025
    risk 0.25cvss 3.8epss 0.00

    An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.

  • CVE-2012-5452Oct 22, 2012
    risk 0.03cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en]…

  • CVE-2012-4773Oct 22, 2012
    risk 0.03cvss —epss 0.03

    Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an…

  • CVE-2012-4771Oct 22, 2012
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to…

  • CVE-2011-5211Oct 22, 2012
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452.