Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Subrion MEDIUM 5.4
CVE-2019-17225

Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.

No fix yet
Fix from $1,600 2019-10-06
Subrion MEDIUM 6.1
CVE-2018-11317

Subrion CMS before 4.1.4 has XSS.

Fix: 4.1.4+
Fix from $1,600 2019-07-03
Subrion Cms MEDIUM 6.1
CVE-2019-11406

Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.

Patch available
Fix from $1,600 2019-05-08
Subrion Cms HIGH 8.8
CVE-2017-18366

Subrion CMS 4.1.5 has CSRF in blog/delete/.

No fix yet
Fix from $1,950 2019-04-15
Subrion Cms MEDIUM 5.4
CVE-2018-16631

Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.

No fix yet
Fix from $1,600 2018-12-04
Subrion Cms HIGH 7.2
CVE-2018-19422EPSS 64%

/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits …

No fix yet
Fix from $1,950 2018-11-21
Subrion MEDIUM 6.1
CVE-2018-15563

_core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.

Mitigation only
Fix from $1,600 2018-10-02
Subrion MEDIUM 6.1
CVE-2018-14840

uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).

Patch available
Fix from $1,600 2018-08-02
Subrion HIGH 8.8
CVE-2017-15063

There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to det…

Fix: after 4.1.5
Fix from $1,950 2017-10-06
Subrion Cms CRITICAL 9.8
CVE-2017-11444EPSS 13%

Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.

Fix: after 4.1.4
Fix from $2,300 2017-07-19
Subrion Cms CRITICAL 9.8
CVE-2017-11445

Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.

Fix: after 4.1.4
Fix from $2,300 2017-07-19
Subrion MEDIUM 6.1
CVE-2017-10795

Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add…

No fix yet
Fix from $1,600 2017-07-02
Subrion Cms CRITICAL 9.8
CVE-2017-6013

Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.

Mitigation only
Fix from $2,300 2017-03-27
Subrion Cms HIGH 8.8
CVE-2017-6002

Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body par…

Mitigation only
Fix from $1,950 2017-03-27
Subrion Cms HIGH 8.8
CVE-2017-6066

Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title…

Mitigation only
Fix from $1,950 2017-03-27
Subrion Cms HIGH 8.8
CVE-2017-6068

Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.

Mitigation only
Fix from $1,950 2017-03-27
Subrion Cms HIGH 8.8
CVE-2017-6069

Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.

Mitigation only
Fix from $1,950 2017-03-27
Subrion CRITICAL 9.8
CVE-2017-5543

includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data i…

Patch available
Fix from $2,300 2017-01-20
Subrion Cms MEDIUM 6.5
CVE-2015-4129

SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized d…

Fix: after 3.3.2
Fix from $1,600 2015-07-05
Subrion Cms HIGH 7.5
CVE-2012-4772

SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parame…

Fix: after 2.2.2
Fix from $1,950 2012-10-22
Subrion Cms MEDIUM 6.8
CVE-2012-4773

Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of adminis…

Fix: after 2.2.2
Fix from $1,600 2012-10-22
Subrion Cms HIGH 7.5
CVE-2011-5212

SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name o…

No fix yet
Fix from $1,950 2012-10-22
Elitius MEDIUM 6.8
CVE-2009-1659

Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upl…

No fix yet
Fix from $1,600 2009-05-18
Elitius MEDIUM 6.8
CVE-2009-1506

SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner…

No fix yet
Fix from $1,600 2009-05-01