PT-2026-49163 · Intelliants · Subrion Cms

·

CVE-2026-12202

·

Published

2026-06-15

·

Updated

2026-06-15

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Intelliants Subrion CMS versions prior to 4.0.4
Description Cross site scripting is possible via the Blocks Endpoint. Remote attackers can exploit this by manipulating the CSS class name argument. Cross site scripting is a type of security flaw that allows attackers to inject malicious scripts into web pages viewed by other users.
Recommendations Update to a version newer than 4.0.3. As a temporary workaround, restrict access to the Blocks Endpoint to minimize the risk of exploitation.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12202

Affected Products

Subrion Cms