Show filters
68 Total Results
Displaying 11-20 of 68
Sort by:
Attacker Value
Unknown

CVE-2021-41502

Disclosure Date: June 11, 2022 (last updated October 07, 2023)
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
Attacker Value
Unknown

CVE-2021-41948

Disclosure Date: April 29, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".
Attacker Value
Unknown

CVE-2021-43464

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().
Attacker Value
Unknown

CVE-2020-18326

Disclosure Date: March 04, 2022 (last updated October 07, 2023)
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
Attacker Value
Unknown

CVE-2020-18325

Disclosure Date: March 04, 2022 (last updated October 07, 2023)
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
Attacker Value
Unknown

CVE-2020-18324

Disclosure Date: March 04, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
Attacker Value
Unknown

CVE-2021-43724

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a SGV file.
Attacker Value
Unknown

CVE-2020-22330

Disclosure Date: August 06, 2021 (last updated November 29, 2024)
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
Attacker Value
Unknown

CVE-2020-22392

Disclosure Date: August 05, 2021 (last updated November 29, 2024)
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
Attacker Value
Unknown

CVE-2020-18155

Disclosure Date: July 14, 2021 (last updated November 28, 2024)
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.