Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-39346
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass dis…
Orangehrm
5.8.1+
HIGH 8.8
CVE-2025-66224
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw i…
Orangehrm
5.8+
HIGH 8.8
CVE-2025-66225
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the u…
Orangehrm
5.8+
HIGH 8.8
CVE-2025-66289
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions w…
Orangehrm
5.8+
HIGH 7.2
CVE-2025-44040
An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions …
Orangehrm
Mitigation only
HIGH 8.1
CVE-2024-36428
OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.
Orangehrm
No fix yet
MEDIUM 5.4
CVE-2022-28985
A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to execute arbitrary web scripts …
Orangehrm
No fix yet
MEDIUM 5.4
CVE-2022-27107
OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter
Orangehrm
No fix yet
MEDIUM 5.4
CVE-2022-27109
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
Orangehrm
No fix yet
MEDIUM 5.4
CVE-2022-27110
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
Orangehrm
No fix yet
MEDIUM 5.3
CVE-2021-28399
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.
Orangehrm
Mitigation only
HIGH 8.1
CVE-2020-29437
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBu…
Orangehrm
4.6.0.1+
MEDIUM 5.4
CVE-2013-1353
Orange HRM 2.7.1 allows XSS via the vacancy name.
Orangehrm
No fix yet
HIGH 8.8
CVE-2019-12839
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenti…
Orangehrm
after 4.3.1
MEDIUM 6.5
CVE-2012-1506
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to …
Orangehrm
after 2.6.12.1
MEDIUM 6.8
CVE-2011-5259
SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL co…
Orangehrm
after 2.6.11
MEDIUM 6.0
CVE-2012-5367
Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the so…
Orangehrm
No fix yet
MEDIUM 5.0
CVE-2011-3766
OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…
Orangehrm
Mitigation only
MEDIUM 6.8
CVE-2010-4798
Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via director…
Orangehrm
No fix yet
MEDIUM 5.0
CVE-2007-5931
The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remot…
Orangehrm
after 2.2.1
HIGH 9.3
CVE-2007-1193
Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vectors.
Orangehrm
Patch available