Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Oroplatform MEDIUM 6.1
CVE-2024-50677

A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in…

No fix yet
Fix from $1,600 2024-12-06
Orocommerce MEDIUM 5.8
CVE-2023-32065

OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be rece…

Fix: 5.0.11 / 5.1.1+
Fix from $1,600 2023-11-28
Client Relationship Management MEDIUM 5.0
CVE-2023-32063

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call ev…

Fix: 5.0.4 / 5.1.1+
Fix from $1,600 2023-11-28
Oroplatform CRITICAL 9.8
CVE-2022-41951

OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Travers…

Fix: 5.0.9+
Fix from $2,300 2023-11-27
Orocommerce MEDIUM 5.4
CVE-2022-31037

OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and…

Fix: after 5.0.3
Fix from $1,600 2022-10-18
Oroplatform HIGH 8.8
CVE-2021-43852

OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties …

Fix: 4.1.14 / 4.2.8+
Fix from $1,950 2022-01-04
Client Relationship Management MEDIUM 5.4
CVE-2021-39198

OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an a…

Fix: after 4.2.5
Fix from $1,600 2021-11-19