Vendor CVEs
Subrion
All CVEs
32 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11444 | Cri | 0.65 | 9.8 | 0.13 | Jul 19, 2017 | Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | ||
| CVE-2024-25400 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2024 | Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly… | ||
| CVE-2017-11445 | Cri | 0.64 | 9.8 | 0.01 | Jul 19, 2017 | Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array. | ||
| CVE-2017-6013 | Cri | 0.64 | 9.8 | 0.02 | Mar 27, 2017 | Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. | ||
| CVE-2023-46947 | Hig | 0.57 | 8.8 | 0.01 | Nov 3, 2023 | Subrion 4.2.1 has a remote command execution vulnerability in the backend. | ||
| CVE-2021-43464 | Hig | 0.57 | 8.8 | 0.01 | Apr 4, 2022 | A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval(). | ||
| CVE-2020-18155 | Cri | 0.57 | 9.8 | 0.01 | Jul 14, 2021 | SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection. | ||
| CVE-2019-7357 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2020 | Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins. | ||
| CVE-2017-6069 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter. | ||
| CVE-2017-6066 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter. | ||
| CVE-2017-6002 | Hig | 0.57 | 8.8 | 0.00 | Mar 27, 2017 | Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter. | ||
| CVE-2026-71292 | Hig | 0.47 | 7.2 | 0.01 | Aug 5, 2026 | Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists the (ASC/DESC) request parameter via in_array, but falls back to the raw, attacker-supplied GET parameter whenever the requested key is not present in the… | ||
| CVE-2021-41947 | Hig | 0.47 | 7.2 | 0.01 | Oct 8, 2021 | A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode. | ||
| CVE-2020-35437 | Med | 0.43 | 6.1 | 0.03 | Dec 26, 2020 | Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. | ||
| CVE-2018-14836 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2018 | Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel. | ||
| CVE-2024-25399 | Med | 0.40 | 6.1 | 0.00 | Feb 27, 2024 | Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php. | ||
| CVE-2023-43875 | Med | 0.40 | 6.1 | 0.01 | Oct 19, 2023 | Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail. | ||
| CVE-2020-23761 | Med | 0.40 | 6.1 | 0.01 | Apr 9, 2021 | Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab. | ||
| CVE-2019-17225 | Med | 0.38 | 5.4 | 0.02 | Oct 6, 2019 | Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. | ||
| CVE-2023-43884 | Med | 0.35 | 5.4 | 0.00 | Sep 28, 2023 | A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter. | ||
| CVE-2023-43830 | Med | 0.35 | 5.4 | 0.01 | Sep 27, 2023 | A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'. | ||
| CVE-2023-43828 | Med | 0.35 | 5.4 | 0.01 | Sep 27, 2023 | A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Title' parameter. | ||
| CVE-2020-22392 | Med | 0.35 | 5.4 | 0.01 | Aug 5, 2021 | Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file. | ||
| CVE-2019-7356 | Med | 0.35 | 5.4 | 0.01 | Nov 4, 2020 | Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter. | ||
| CVE-2020-22330 | Med | 0.33 | 6.1 | 0.01 | Aug 6, 2021 | Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page. | ||
| CVE-2022-37059 | Med | 0.31 | 4.8 | 0.01 | Aug 29, 2022 | Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field | ||
| CVE-2018-14835 | Med | 0.28 | 5.4 | 0.01 | Aug 2, 2018 | Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas. | ||
| CVE-2025-56556 | Low | 0.25 | 3.8 | 0.00 | Sep 11, 2025 | An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool. | ||
| CVE-2012-5452 | 0.03 | — | 0.05 | Oct 22, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en]… | |||
| CVE-2012-4773 | 0.03 | — | 0.03 | Oct 22, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an… | |||
| CVE-2012-4771 | 0.03 | — | 0.04 | Oct 22, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to… | |||
| CVE-2011-5211 | 0.03 | — | 0.04 | Oct 22, 2012 | Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452. |
- risk 0.65cvss 9.8epss 0.13
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
- risk 0.64cvss 9.8epss 0.01
Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly…
- risk 0.64cvss 9.8epss 0.01
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
- risk 0.64cvss 9.8epss 0.02
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
- risk 0.57cvss 8.8epss 0.01
Subrion 4.2.1 has a remote command execution vulnerability in the backend.
- risk 0.57cvss 8.8epss 0.01
A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().
- risk 0.57cvss 9.8epss 0.01
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
- risk 0.57cvss 8.8epss 0.00
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
- risk 0.47cvss 7.2epss 0.01
Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists the (ASC/DESC) request parameter via in_array, but falls back to the raw, attacker-supplied GET parameter whenever the requested key is not present in the…
- risk 0.47cvss 7.2epss 0.01
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
- risk 0.43cvss 6.1epss 0.03
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
- risk 0.42cvss 6.5epss 0.01
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
- risk 0.40cvss 6.1epss 0.00
Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
- risk 0.40cvss 6.1epss 0.01
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.
- risk 0.38cvss 5.4epss 0.02
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
- risk 0.35cvss 5.4epss 0.00
A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter.
- risk 0.35cvss 5.4epss 0.01
A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'.
- risk 0.35cvss 5.4epss 0.01
A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Title' parameter.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
- risk 0.35cvss 5.4epss 0.01
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
- risk 0.33cvss 6.1epss 0.01
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
- risk 0.31cvss 4.8epss 0.01
Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field
- risk 0.28cvss 5.4epss 0.01
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
- risk 0.25cvss 3.8epss 0.00
An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.
- CVE-2012-5452Oct 22, 2012risk 0.03cvss —epss 0.05
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en]…
- CVE-2012-4773Oct 22, 2012risk 0.03cvss —epss 0.03
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an…
- CVE-2012-4771Oct 22, 2012risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to…
- CVE-2011-5211Oct 22, 2012risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452.