Known Vulnerabilities for Subrion Cms by Intelliants

Listed below are 10 of the newest known vulnerabilities associated with "Subrion Cms" by "Intelliants".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-43875 json Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute... 6.1 - MEDIUM 2023-10-19 2023-10-30
CVE-2022-43121 json A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to ex... 6.1 - MEDIUM 2022-11-09 2022-11-09
CVE-2022-43120 json A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attack... 6.1 - MEDIUM 2022-11-09 2022-11-09
CVE-2022-37059 json Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field 4.8 - MEDIUM 2022-08-29 2022-09-01
CVE-2021-43724 json A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin A... 4.8 - MEDIUM 2022-02-24 2022-03-02
CVE-2021-43464 json A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the inf... 8.8 - HIGH 2022-04-04 2022-04-12
CVE-2021-41947 json A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode. 7.2 - HIGH 2021-10-08 2021-11-30
CVE-2021-41502 json An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute mal... 5.4 - MEDIUM 2022-06-11 2022-06-17
CVE-2020-35437 json Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_co... 6.1 - MEDIUM 2020-12-26 2022-07-17
CVE-2020-22392 json Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file. 5.4 - MEDIUM 2021-08-05 2021-08-11

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationIntelliantsSubrion Cms4.2.1
ApplicationIntelliantsSubrion Cms4.2.0
ApplicationIntelliantsSubrion Cms4.1.5.20
ApplicationIntelliantsSubrion Cms4.1.5
ApplicationIntelliantsSubrion Cms4.1.4
ApplicationIntelliantsSubrion Cms4.1.3
ApplicationIntelliantsSubrion Cms4.1.2
ApplicationIntelliantsSubrion Cms4.1.1
ApplicationIntelliantsSubrion Cms4.1.0
ApplicationIntelliantsSubrion Cms4.0.5.10
ApplicationIntelliantsSubrion Cms4.0.5
ApplicationIntelliantsSubrion Cms4.0.4
ApplicationIntelliantsSubrion Cms4.0.3
ApplicationIntelliantsSubrion Cms4.0.2
ApplicationIntelliantsSubrion Cms4.0.1
ApplicationIntelliantsSubrion Cms4.0.0
ApplicationIntelliantsSubrion Cms3.3.5
ApplicationIntelliantsSubrion Cms3.3.4
ApplicationIntelliantsSubrion Cms3.3.3
ApplicationIntelliantsSubrion Cms3.3.2
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report