CVE Tools

Subrion CMS

42 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Subrion CMS, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Subrion CMS CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Subrion CMS CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-091
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-061
2026-070
2026-081
2026-092

Severity

How the 42 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical37%
  • High1229%
  • Medium2560%
  • Low25%

Latest CVEs

The 15 most recently published vulnerabilities affecting Subrion CMS.

  1. CVE-2026-96773Intelliants Subrion CMS Login Page login.php authorize redirect4.3
  2. CVE-2026-96772Intelliants Subrion CMS actions.json assign-owner information disclosure5.3
  3. CVE-2026-72604Intelliants Subrion CMS - Path Traversal6.5
  4. CVE-2026-12202Intelliants Subrion CMS Blocks Endpoint cross site scripting2.4
  5. CVE-2025-70958Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser ...6.1
  6. CVE-2025-56556An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated...3.8
  7. CVE-2024-25399Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.6.1
  8. CVE-2023-43875Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, d...6.1
  9. CVE-2022-43120A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec...6.1
  10. CVE-2022-43121A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into ...6.1
  11. CVE-2022-37059Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field4.8
  12. CVE-2021-41502An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, clos...5.4
  13. CVE-2021-43464A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().8.8
  14. CVE-2020-18325Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.6.1
  15. CVE-2020-18324Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store