Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2019-17225
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
Subrion
No fix yet
MEDIUM 6.1
CVE-2018-11317
Subrion CMS before 4.1.4 has XSS.
Subrion
4.1.4+
MEDIUM 6.1
CVE-2019-11406
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
Subrion Cms
Patch available
HIGH 8.8
CVE-2017-18366
Subrion CMS 4.1.5 has CSRF in blog/delete/.
Subrion Cms
No fix yet
MEDIUM 5.4
CVE-2018-16631
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
Subrion Cms
No fix yet
HIGH 7.2
CVE-2018-19422EPSS 64%
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits …
Subrion Cms
No fix yet
MEDIUM 6.1
CVE-2018-15563
_core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.
Subrion
Mitigation only
MEDIUM 6.1
CVE-2018-14840
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
Subrion
Patch available
HIGH 8.8
CVE-2017-15063
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to det…
Subrion
after 4.1.5
CRITICAL 9.8
CVE-2017-11444EPSS 13%
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
Subrion Cms
after 4.1.4
CRITICAL 9.8
CVE-2017-11445
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
Subrion Cms
after 4.1.4
MEDIUM 6.1
CVE-2017-10795
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add…
Subrion
No fix yet
CRITICAL 9.8
CVE-2017-6013
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
Subrion Cms
Mitigation only
HIGH 8.8
CVE-2017-6002
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body par…
Subrion Cms
Mitigation only
HIGH 8.8
CVE-2017-6066
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title…
Subrion Cms
Mitigation only
HIGH 8.8
CVE-2017-6068
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
Subrion Cms
Mitigation only
HIGH 8.8
CVE-2017-6069
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
Subrion Cms
Mitigation only
CRITICAL 9.8
CVE-2017-5543
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data i…
Subrion
Patch available
MEDIUM 6.5
CVE-2015-4129
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized d…
Subrion Cms
after 3.3.2
HIGH 7.5
CVE-2012-4772
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parame…
Subrion Cms
after 2.2.2
MEDIUM 6.8
CVE-2012-4773
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of adminis…
Subrion Cms
after 2.2.2
HIGH 7.5
CVE-2011-5212
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name o…
Subrion Cms
No fix yet
MEDIUM 6.8
CVE-2009-1659
Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upl…
Elitius
No fix yet
MEDIUM 6.8
CVE-2009-1506
SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner…
Elitius
No fix yet