Vulnerabilities > Intelliants > Subrion > Low

DATE CVE VULNERABILITY TITLE RISK
2022-04-29 CVE-2021-41948 Cross-site Scripting vulnerability in Intelliants Subrion
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".
3.5
2020-11-04 CVE-2019-7356 Cross-site Scripting vulnerability in Intelliants Subrion 4.2.1
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
3.5
2019-10-06 CVE-2019-17225 Cross-site Scripting vulnerability in Intelliants Subrion 4.2.1
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
3.5
2018-09-01 CVE-2018-16327 Cross-site Scripting vulnerability in Intelliants Subrion 4.2.1
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
3.5