CVE-2018-14835: Subrion CMS
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
Affected products
- Subrion Subrion CMS: version 4.2.1 only
Published 2018-08-02. Last modified 2026-06-17.