CVE-2018-14835: Subrion CMS

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.

Affected products

  • Subrion Subrion CMS: version 4.2.1 only

Published 2018-08-02. Last modified 2026-06-17.