Vulnerabilities (CVE)

Filtered by vendor Intelliants Subscribe
Filtered by product Subrion Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-35437 1 Intelliants 1 Subrion Cms 2022-07-17 4.3 MEDIUM 6.1 MEDIUM
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
CVE-2021-41502 1 Intelliants 1 Subrion Cms 2022-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
CVE-2020-22392 1 Intelliants 1 Subrion Cms 2021-08-11 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
CVE-2019-11406 1 Intelliants 1 Subrion Cms 2019-05-09 4.3 MEDIUM 6.1 MEDIUM
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
CVE-2018-16631 1 Intelliants 1 Subrion Cms 2019-02-26 3.5 LOW 5.4 MEDIUM
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
CVE-2018-16629 1 Intelliants 1 Subrion Cms 2019-02-26 3.5 LOW 4.8 MEDIUM
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.