- EPSS 0.25%
- Veröffentlicht 24.09.2026 00:45:12
- Zuletzt bearbeitet 24.09.2026 14:40:36
A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers::authorize of the file front/login.php of the component Login Page. This manipulation of the argument $_SERVER['HTTP_REFERER'] caus...
CVE-2026-96772
- EPSS 0.29%
- Veröffentlicht 24.09.2026 00:30:09
- Zuletzt bearbeitet 24.09.2026 16:17:27
A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of the argument q results in information disclosure. The attack can be executed r...
CVE-2026-72604
- EPSS 0.33%
- Veröffentlicht 11.08.2026 11:15:25
- Zuletzt bearbeitet 28.08.2026 18:51:39
A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to ...
CVE-2026-12202
- EPSS 0.21%
- Veröffentlicht 15.06.2026 00:45:08
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS class name leads to cross site scripting. The attack m...
CVE-2025-70958
- EPSS 0.25%
- Veröffentlicht 02.02.2026 23:16:02
- Zuletzt bearbeitet 11.02.2026 20:33:17
Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpw...
CVE-2025-56556
- EPSS 0.2%
- Veröffentlicht 11.09.2025 00:00:00
- Zuletzt bearbeitet 25.11.2025 15:15:52
An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.
CVE-2024-25399
- EPSS 0.35%
- Veröffentlicht 27.02.2024 16:15:46
- Zuletzt bearbeitet 27.03.2025 14:55:13
Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
CVE-2023-43875
- EPSS 0.76%
- Veröffentlicht 19.10.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:24:56
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.
CVE-2022-43120
- EPSS 0.5%
- Veröffentlicht 09.11.2022 16:15:18
- Zuletzt bearbeitet 01.05.2025 15:15:56
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
CVE-2022-43121
- EPSS 0.59%
- Veröffentlicht 09.11.2022 16:15:18
- Zuletzt bearbeitet 01.05.2025 16:15:23
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.