Subrion
Products
3- 12 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11444 | Cri | 0.65 | 9.8 | 0.13 | Jul 19, 2017 | Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | ||
| CVE-2017-11445 | Cri | 0.64 | 9.8 | 0.01 | Jul 19, 2017 | Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array. | ||
| CVE-2017-6013 | Cri | 0.64 | 9.8 | 0.02 | Mar 27, 2017 | Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. | ||
| CVE-2017-6069 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter. | ||
| CVE-2017-6066 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter. | ||
| CVE-2017-6002 | Hig | 0.57 | 8.8 | 0.00 | Mar 27, 2017 | Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter. | ||
| CVE-2020-35437 | Med | 0.43 | 6.1 | 0.03 | Dec 26, 2020 | Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. | ||
| CVE-2018-14836 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2018 | Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel. | ||
| CVE-2019-17225 | Med | 0.38 | 5.4 | 0.02 | Oct 6, 2019 | Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. | ||
| CVE-2019-7356 | Med | 0.35 | 5.4 | 0.01 | Nov 4, 2020 | Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter. | ||
| CVE-2018-14835 | Med | 0.28 | 5.4 | 0.01 | Aug 2, 2018 | Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas. | ||
| CVE-2012-5452 | 0.03 | — | 0.05 | Oct 22, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en]… | |||
| CVE-2012-4773 | 0.03 | — | 0.03 | Oct 22, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an… | |||
| CVE-2012-4771 | 0.03 | — | 0.04 | Oct 22, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to… | |||
| CVE-2011-5211 | 0.03 | — | 0.04 | Oct 22, 2012 | Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452. |
- risk 0.65cvss 9.8epss 0.13
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
- risk 0.64cvss 9.8epss 0.01
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
- risk 0.64cvss 9.8epss 0.02
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
- risk 0.57cvss 8.8epss 0.00
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
- risk 0.43cvss 6.1epss 0.03
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
- risk 0.42cvss 6.5epss 0.01
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
- risk 0.38cvss 5.4epss 0.02
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
- risk 0.35cvss 5.4epss 0.01
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
- risk 0.28cvss 5.4epss 0.01
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
- CVE-2012-5452Oct 22, 2012risk 0.03cvss —epss 0.05
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en]…
- CVE-2012-4773Oct 22, 2012risk 0.03cvss —epss 0.03
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an…
- CVE-2012-4771Oct 22, 2012risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to…
- CVE-2011-5211Oct 22, 2012risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452.