Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Orchard Cms CRITICAL 9.0
CVE-2022-37720

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a c…

Mitigation only
Fix from $2,300 2022-11-25
Orchardcore MEDIUM 5.4
CVE-2022-32173

In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML…

Fix: 1.4.0+
Fix from $1,600 2022-10-03
Orchardcore MEDIUM 5.4
CVE-2022-0822

Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

Fix: 1.3.0+
Fix from $1,600 2022-03-11
Orchardcore MEDIUM 6.5
CVE-2022-0821

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

Fix: 1.3.0+
Fix from $1,600 2022-03-11
Orchardcore MEDIUM 6.1
CVE-2022-0820

Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.

Fix: 1.3.0+
Fix from $1,600 2022-03-11
Orchardcore MEDIUM 5.4
CVE-2022-0243

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

Fix: 1.2.2+
Fix from $1,600 2022-01-19
Orchardcore MEDIUM 5.4
CVE-2022-0274

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

Fix: 1.2.2+
Fix from $1,600 2022-01-19
Orchardcore MEDIUM 5.4
CVE-2022-0159

orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 1.2.1+
Fix from $1,600 2022-01-12
Orchard Core HIGH 8.8
CVE-2021-25966

In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a…

No fix yet
Fix from $1,950 2021-10-10