Intelliants maintains a narrowly focused product portfolio centered on web content management and syndication platforms, where despite limited product breadth, the vendor's disclosures occupy a prominent position in the landscape. Vulnerabilities affecting Intelliants skew toward web application input-handling classes, with cross-site scripting, SQL injection, cross-site request forgery, and code injection comprising the durable exposure pattern. These weaknesses recur across products including Subrion CMS, Elitius, and eSyncdicat, reflecting the challenges of securing templating, parameter handling, and user-input sanitization in content-management and data-integration systems. The vendor's disclosures have an elevated tendency to acquire public exploit code, which is expected for widely deployed web applications; defenders should treat Intelliants product instances as regular-maintenance targets and prioritize input-validation patches. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intelliants over time
Signals from CVEs in this vendor scope (65 CVEs).
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19422HIGH /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these. | Nov 21, 2018 | 7.2 | 77 | NO | YES |
CVE-2017-11444CRITICAL Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | Jul 19, 2017 | 9.8 | 40 | NO | YES |
CVE-2012-4772HIGH SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter. | Oct 22, 2012 | 7.5 | 33 | NO | YES |
CVE-2011-5212HIGH SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field. | Oct 22, 2012 | 7.5 | 33 | NO | YES |
CVE-2018-14840MEDIUM uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads). | Aug 2, 2018 | 6.1 | 32 | NO | YES |
CVE-2017-5543CRITICAL includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login requ | Jan 20, 2017 | 9.8 | 32 | NO | NO |
CVE-2020-35437MEDIUM Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. | Dec 26, 2020 | 6.1 | 31 | NO | YES |
CVE-2012-4773MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, | Oct 22, 2012 | 6.8 | 31 | NO | YES |
CVE-2020-18155CRITICAL SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection. | Jul 14, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-17225MEDIUM Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. | Oct 6, 2019 | 5.4 | 29 | NO | YES |
Signals from CVEs in this vendor scope (65 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intelliants.
Media articles that mention a CVE ID that affects a product developed by Intelliants — matched by CVE ID, not by vendor name.