Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-39346 OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass dis… Orangehrm 5.8.1+ Fix from $1,6002026-04-07 HIGH 8.8 CVE-2025-66224 OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw i… Orangehrm 5.8+ Fix from $1,9502025-11-29 HIGH 8.8 CVE-2025-66225 OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the u… Orangehrm 5.8+ Fix from $1,9502025-11-29 HIGH 8.8 CVE-2025-66289 OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions w… Orangehrm 5.8+ Fix from $1,9502025-11-29 HIGH 7.2 CVE-2025-44040 An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions … Orangehrm Mitigation only Fix from $1,9502025-05-21 HIGH 8.1 CVE-2024-36428 OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection. Orangehrm No fix yet Fix from $1,9502024-05-27 MEDIUM 5.4 CVE-2022-28985 A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to execute arbitrary web scripts … Orangehrm No fix yet Fix from $1,6002022-05-20 MEDIUM 5.4 CVE-2022-27107 OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter Orangehrm No fix yet Fix from $1,6002022-04-06 MEDIUM 5.4 CVE-2022-27109 OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability. Orangehrm No fix yet Fix from $1,6002022-04-06 MEDIUM 5.4 CVE-2022-27110 OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint. Orangehrm No fix yet Fix from $1,6002022-04-06 MEDIUM 5.3 CVE-2021-28399 OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function. Orangehrm Mitigation only Fix from $1,6002021-04-26 HIGH 8.1 CVE-2020-29437 SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBu… Orangehrm 4.6.0.1+ Fix from $1,9502021-01-05 MEDIUM 5.4 CVE-2013-1353 Orange HRM 2.7.1 allows XSS via the vacancy name. Orangehrm No fix yet Fix from $1,6002020-02-10 HIGH 8.8 CVE-2019-12839 In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenti… Orangehrm after 4.3.1 Fix from $1,9502019-06-15 MEDIUM 6.5 CVE-2012-1506 SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to … Orangehrm after 2.6.12.1 Fix from $1,6002014-09-17 MEDIUM 6.8 CVE-2011-5259 SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL co… Orangehrm after 2.6.11 Fix from $1,6002013-02-12 MEDIUM 6.0 CVE-2012-5367 Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the so… Orangehrm No fix yet Fix from $1,6002012-12-03 MEDIUM 5.0 CVE-2011-3766 OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in… Orangehrm Mitigation only Fix from $1,6002011-09-24 MEDIUM 6.8 CVE-2010-4798 Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via director… Orangehrm No fix yet Fix from $1,6002011-04-27 MEDIUM 5.0 CVE-2007-5931 The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remot… Orangehrm after 2.2.1 Fix from $1,6002007-11-10 HIGH 9.3 CVE-2007-1193 Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vectors. Orangehrm Patch available Fix from $1,9502007-03-02