Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.64%—Intelliants Subrion6/8/202117/6/2026
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
ModificadaMedia (5.4)0.62%—Intelliants Subrion CMS5/8/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
ModificadaCrítica (9.8)1.3%—Intelliants Subrion14/7/202117/6/2026
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
ModificadaMedia (6.1)1.0%—Intelliants Subrion9/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.
ModificadaMedia (6.1)3.1%💥 ExploitIntelliants Subrion CMS26/12/202017/6/2026
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
ModificadaAlta (8.8)1.4%💥 PoCIntelliants Subrion CMS10/11/202017/6/2026
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
ModificadaMedia (5.4)0.75%💥 PoCIntelliants Subrion4/11/202017/6/2026
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
ModificadaAlta (8.1)0.68%—Intelliants Subrion15/5/202017/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate the CSRF token for a GET request. An…
ModificadaMedia (6.1)0.95%—Intelliants Subrion15/5/202017/6/2026
An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user's browser without proper output encoding.
ModificadaMedia (6.5)0.86%—Intelliants Subrion29/4/202017/6/2026
admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit.
ModificadaAlta (7.8)0.86%—Intelliants Subrion29/4/202017/6/2026
Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.
ModificadaMedia (6.5)0.94%—Intelliants Subrion29/4/202017/6/2026
Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.
ModificadaAlta (8.8)0.51%—Intelliants Subrion17/3/202017/6/2026
Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
ModificadaMedia (5.4)1.9%💥 ExploitIntelliants Subrion6/10/201917/6/2026
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
ModificadaMedia (6.1)0.91%—Intelliants Subrion3/7/201917/6/2026
Subrion CMS before 4.1.4 has XSS.
ModificadaMedia (6.1)0.95%—Intelliants Subrion CMS8/5/201917/6/2026
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
ModificadaAlta (8.8)0.65%—Intelliants Subrion CMS15/4/201917/6/2026
Subrion CMS 4.1.5 has CSRF in blog/delete/.
ModificadaMedia (5.4)0.56%—Intelliants Subrion CMS4/12/201817/6/2026
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
ModificadaMedia (4.8)0.56%—Intelliants Subrion CMS4/12/201817/6/2026
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
ModificadaAlta (7.2)64%💥 ExploitIntelliants Subrion CMS21/11/201817/6/2026
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
ModificadaMedia (6.1)0.69%—Intelliants Subrion2/10/201817/6/2026
_core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.
ModificadaMedia (4.8)0.62%—Intelliants Subrion1/9/201817/6/2026
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
ModificadaMedia (6.1)3.7%💥 ExploitIntelliants Subrion2/8/201817/6/2026
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
ModificadaMedia (6.5)1.00%—Subrion CMS2/8/201817/6/2026
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
ModificadaMedia (5.4)0.74%—Subrion CMS2/8/201817/6/2026
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
Orbitaley — Vulnerabilidades