Filtered by vendor Subrion Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-56556 1 Subrion 1 Cms 2025-09-15 6.5 Medium
An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.
CVE-2018-14836 1 Subrion 1 Subrion Cms 2024-11-21 N/A
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
CVE-2018-14835 1 Subrion 1 Subrion Cms 2024-11-21 N/A
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.