Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Orangehrm HIGH 7.2
CVE-2025-44040

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions …

Mitigation only
Fix from $1,950 2025-05-21
Orangehrm HIGH 8.1
CVE-2024-36428

OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

No fix yet
Fix from $1,950 2024-05-27
Orangehrm MEDIUM 5.4
CVE-2022-28985

A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to execute arbitrary web scripts …

No fix yet
Fix from $1,600 2022-05-20
Orangehrm MEDIUM 5.4
CVE-2022-27107

OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter

No fix yet
Fix from $1,600 2022-04-06
Orangehrm MEDIUM 5.4
CVE-2022-27109

OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.

No fix yet
Fix from $1,600 2022-04-06
Orangehrm MEDIUM 5.4
CVE-2022-27110

OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.

No fix yet
Fix from $1,600 2022-04-06
Orangehrm MEDIUM 5.3
CVE-2021-28399

OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.

Mitigation only
Fix from $1,600 2021-04-26
Orangehrm MEDIUM 5.4
CVE-2013-1353

Orange HRM 2.7.1 allows XSS via the vacancy name.

No fix yet
Fix from $1,600 2020-02-10
Orangehrm MEDIUM 6.0
CVE-2012-5367

Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the so…

No fix yet
Fix from $1,600 2012-12-03
Orangehrm MEDIUM 5.0
CVE-2011-3766

OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

Mitigation only
Fix from $1,600 2011-09-24
Orangehrm MEDIUM 6.8
CVE-2010-4798

Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via director…

No fix yet
Fix from $1,600 2011-04-27