Known Vulnerabilities for products from Orchardcore
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Orchardcore".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-37720 json | Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author o... | Not Provided | 2022-11-25 | 2026-07-09 |
| CVE-2022-32173 json | In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to ... | 5.4 - MEDIUM | 2022-10-03 | 2023-11-07 |
| CVE-2022-0822 json | Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0. | 5.4 - MEDIUM | 2022-03-11 | 2022-03-18 |
| CVE-2022-0821 json | Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0. | 6.5 - MEDIUM | 2022-03-11 | 2023-07-24 |
| CVE-2022-0820 json | Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0. | 6.1 - MEDIUM | 2022-03-11 | 2022-03-18 |
| CVE-2022-0274 json | Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2. | 5.4 - MEDIUM | 2022-01-19 | 2022-01-25 |
| CVE-2022-0243 json | Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2. | 5.4 - MEDIUM | 2022-01-19 | 2022-01-25 |
| CVE-2022-0159 json | orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 5.4 - MEDIUM | 2022-01-12 | 2022-01-18 |
| CVE-2021-25966 json | In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination a... | 8.8 - HIGH | 2021-10-10 | 2022-02-25 |