Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Orangehrm MEDIUM 5.4
CVE-2026-39346

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass dis…

Fix: 5.8.1+
Fix from $1,600 2026-04-07
Orangehrm HIGH 8.8
CVE-2025-66224

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw i…

Fix: 5.8+
Fix from $1,950 2025-11-29
Orangehrm HIGH 8.8
CVE-2025-66225

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the u…

Fix: 5.8+
Fix from $1,950 2025-11-29
Orangehrm HIGH 8.8
CVE-2025-66289

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions w…

Fix: 5.8+
Fix from $1,950 2025-11-29
Orangehrm HIGH 7.2
CVE-2025-44040

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions …

Mitigation only
Fix from $1,950 2025-05-21
Orangehrm HIGH 8.1
CVE-2024-36428

OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

No fix yet
Fix from $1,950 2024-05-27
Orangehrm MEDIUM 5.4
CVE-2022-28985

A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to execute arbitrary web scripts …

No fix yet
Fix from $1,600 2022-05-20
Orangehrm MEDIUM 5.4
CVE-2022-27107

OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter

No fix yet
Fix from $1,600 2022-04-06
Orangehrm MEDIUM 5.4
CVE-2022-27109

OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.

No fix yet
Fix from $1,600 2022-04-06
Orangehrm MEDIUM 5.4
CVE-2022-27110

OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.

No fix yet
Fix from $1,600 2022-04-06
Orangehrm MEDIUM 5.3
CVE-2021-28399

OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.

Mitigation only
Fix from $1,600 2021-04-26
Orangehrm HIGH 8.1
CVE-2020-29437

SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBu…

Fix: 4.6.0.1+
Fix from $1,950 2021-01-05
Orangehrm MEDIUM 5.4
CVE-2013-1353

Orange HRM 2.7.1 allows XSS via the vacancy name.

No fix yet
Fix from $1,600 2020-02-10
Orangehrm HIGH 8.8
CVE-2019-12839

In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenti…

Fix: after 4.3.1
Fix from $1,950 2019-06-15
Orangehrm MEDIUM 6.5
CVE-2012-1506

SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to …

Fix: after 2.6.12.1
Fix from $1,600 2014-09-17
Orangehrm MEDIUM 6.8
CVE-2011-5259

SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL co…

Fix: after 2.6.11
Fix from $1,600 2013-02-12
Orangehrm MEDIUM 6.0
CVE-2012-5367

Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the so…

No fix yet
Fix from $1,600 2012-12-03
Orangehrm MEDIUM 5.0
CVE-2011-3766

OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

Mitigation only
Fix from $1,600 2011-09-24
Orangehrm MEDIUM 6.8
CVE-2010-4798

Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via director…

No fix yet
Fix from $1,600 2011-04-27
Orangehrm MEDIUM 5.0
CVE-2007-5931

The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remot…

Fix: after 2.2.1
Fix from $1,600 2007-11-10
Orangehrm HIGH 9.3
CVE-2007-1193

Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vectors.

Patch available
Fix from $1,950 2007-03-02