Intelliants has 5 CVEs on record between 2022 and 2026. 2 were published in the last 90 days. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. Most affected products: subrion_cms (3), Subrion CMS (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2020-18326High· 8.8Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfull…61CVE-2020-18325Medium· 6.1Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.46CVE-2020-18324Medium· 6.1Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.46CVE-2026-96772Medium· 5.3A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.129CVE-2026-96773Medium· 4.3A weakness has been identified in Intelliants Subrion CMS up to 4.2.124
Intelliants vulnerabilities
CVEs affecting Intelliants, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-96773Medium· 4.3A weakness has been identified in Intelliants Subrion CMS up to 4.2.1
A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers::authorize of the file front/login.php of the component Login Page. This manipulation of the argument $_SERVER['HTTP_R…
CVE-2026-96772Medium· 5.3A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1
A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of the argument q results in information disclosure. The attack can …
CVE-2020-18326High· 8.8PoCCross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfull…
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfull…
CVE-2020-18325Medium· 6.1PoCMultilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
CVE-2020-18324Medium· 6.1PoCCross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.