{"id":"CVE-2018-14835","aliases":["GHSA-c8mg-wp7h-f2pf"],"url":"https://o3.security/vulnerability/CVE-2018-14835","summary":"Subrion CMS XSS","details":"Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.","published":"2018-08-02T00:29:00.217Z","modified":"2026-07-08T14:14:36.492466Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"intelliants/subrion","fixedVersion":null}],"fix":{"url":"https://github.com/intelliants/subrion/pull/763/commits","label":"intelliants/subrion#763"},"references":[{"type":"FIX","url":"https://github.com/intelliants/subrion/pull/763/commits"},{"type":"EVIDENCE","url":"https://github.com/intelliants/subrion/issues/760"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:14:36.492466Z"}}