Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2019-17225 Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. Subrion No fix yet Fix from $1,6002019-10-06 MEDIUM 6.1 CVE-2018-11317 Subrion CMS before 4.1.4 has XSS. Subrion 4.1.4+ Fix from $1,6002019-07-03 MEDIUM 6.1 CVE-2019-11406 Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter. Subrion Cms Patch available Fix from $1,6002019-05-08 HIGH 8.8 CVE-2017-18366 Subrion CMS 4.1.5 has CSRF in blog/delete/. Subrion Cms No fix yet Fix from $1,9502019-04-15 MEDIUM 5.4 CVE-2018-16631 Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. Subrion Cms No fix yet Fix from $1,6002018-12-04 HIGH 7.2 CVE-2018-19422EPSS 64% /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits … Subrion Cms No fix yet Fix from $1,9502018-11-21 MEDIUM 6.1 CVE-2018-15563 _core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter. Subrion Mitigation only Fix from $1,6002018-10-02 MEDIUM 6.1 CVE-2018-14840 uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads). Subrion Patch available Fix from $1,6002018-08-02 HIGH 8.8 CVE-2017-15063 There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to det… Subrion after 4.1.5 Fix from $1,9502017-10-06 CRITICAL 9.8 CVE-2017-11444EPSS 13% Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. Subrion Cms after 4.1.4 Fix from $2,3002017-07-19 CRITICAL 9.8 CVE-2017-11445 Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array. Subrion Cms after 4.1.4 Fix from $2,3002017-07-19 MEDIUM 6.1 CVE-2017-10795 Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add… Subrion No fix yet Fix from $1,6002017-07-02 CRITICAL 9.8 CVE-2017-6013 Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. Subrion Cms Mitigation only Fix from $2,3002017-03-27 HIGH 8.8 CVE-2017-6002 Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body par… Subrion Cms Mitigation only Fix from $1,9502017-03-27 HIGH 8.8 CVE-2017-6066 Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title… Subrion Cms Mitigation only Fix from $1,9502017-03-27 HIGH 8.8 CVE-2017-6068 Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter. Subrion Cms Mitigation only Fix from $1,9502017-03-27 HIGH 8.8 CVE-2017-6069 Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter. Subrion Cms Mitigation only Fix from $1,9502017-03-27 CRITICAL 9.8 CVE-2017-5543 includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data i… Subrion Patch available Fix from $2,3002017-01-20 MEDIUM 6.5 CVE-2015-4129 SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized d… Subrion Cms after 3.3.2 Fix from $1,6002015-07-05 HIGH 7.5 CVE-2012-4772 SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parame… Subrion Cms after 2.2.2 Fix from $1,9502012-10-22 MEDIUM 6.8 CVE-2012-4773 Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of adminis… Subrion Cms after 2.2.2 Fix from $1,6002012-10-22 HIGH 7.5 CVE-2011-5212 SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name o… Subrion Cms No fix yet Fix from $1,9502012-10-22 MEDIUM 6.8 CVE-2009-1659 Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upl… Elitius No fix yet Fix from $1,6002009-05-18 MEDIUM 6.8 CVE-2009-1506 SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner… Elitius No fix yet Fix from $1,6002009-05-01