Powerful opensource content management system written in PHP5 + MySQL.
intelliants/subrion has critical vulnerabilities — do not use
Update to >= 4.2.2 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2023-46947 | Subrion remote command execution vulnerability | — |
| medium | CVE-2022-43120 | Subrion CMS is vulnerable to Cross-Site Scripting (XSS) | — |
| high | CVE-2020-12468 | Subrion CMS CSV injection via Export Language | — |
| medium | CVE-2023-43828 | Subrion CMS Cross-site Scripting vulnerability in /panel/languages | — |
| medium | CVE-2023-43875 | Subrion CMS vulnerable to Cross-site Scripting | — |
| high | CVE-2018-19422 | Subrion CMS RCE Vulnerability | 4.2.2 |
| critical | CVE-2020-18155 | SQL Injection in Subrion CMS | — |
| medium | CVE-2023-43884 | Subrion CMS Cross-site Scripting vulnerability | — |
| high | CVE-2020-18326 | Cross Site Request Forgery in intelliants/subrion | — |
| medium | CVE-2025-70958 | Subrion CMS vulnerable to cross-site scripting | — |
| medium | CVE-2020-12469 | Subrion CMS PHP Object Injection | — |
| high | CVE-2021-43464 | Remote code execution in Subrion | — |
| medium | CVE-2025-56556 | Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool | — |
| medium | CVE-2020-22392 | Cross Site Scripting in Subrion CMS | — |
| medium | CVE-2020-22330 | Subrion Cross-Site Scripting (XSS) vulnerability | 4.2.2 |
| medium | CVE-2022-43121 | Subrion CMS is vulnerable to Cross-Site Scripting (XSS) | — |
| medium | CVE-2021-41948 | Subrion CMS Cross-site Scripting (XSS) vulnerability in the `contact us` plugin | — |
| medium | CVE-2021-41502 | Cross site scripting in intelliants/subrion | — |
| medium | CVE-2020-18325 | Cross-site Scripting in intelliants/subrion | — |
| medium | CVE-2024-25399 | Subrion CMS vulnerable to Cross Site Scripting | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/composer/intelliants/subrionLast updated · 2018-06-14T12:04:55+00:00