Products: 2
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-70958

    Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.

    Last Modified: Feb 11, 2026
    Published: Feb 02, 2026

    CVE-2025-56556

    An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.

    Last Modified: Nov 25, 2025
    Published: Sep 11, 2025

    CVE-2018-14835

    Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.

    Last Modified: Nov 21, 2024
    Published: Aug 02, 2018

    CVE-2018-14836

    Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.

    Last Modified: Nov 21, 2024
    Published: Aug 02, 2018
    Items Per Page
    Subrion Vulnerabilities & Security CVEs | CVE-DB