Orchardcore
3 CVEs tracked since 2022. Since Jan 2022, none of them reached CISA KEV.
Orchardcore CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-01 | 3 | 0 |
Products
The products that kept showing up in Orchardcore's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Orchardcore.
- CVE-2020-37019Orchard Core RC1 - Persistent Cross-Site Scripting6.4
- CVE-2022-37720Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog pos...9.0
- CVE-2022-32173OrchardCore - HTML Injection5.4
- CVE-2022-0822Cross-site Scripting (XSS) - Reflected in orchardcms/orchardcore5.4
- CVE-2022-0821Improper Authorization in orchardcms/orchardcore6.5
- CVE-2022-0820Cross-site Scripting (XSS) - Stored in orchardcms/orchardcore6.1
- CVE-2022-0243Cross-site Scripting (XSS) - Stored in orchardcms/orchardcore5.4
- CVE-2022-0274Cross-site Scripting (XSS) - Stored in orchardcms/orchardcore5.4
- CVE-2022-0159Cross-site Scripting (XSS) - Stored in orchardcms/orchardcore5.4
- CVE-2021-25966Orchard Core CMS - Improper Session Termination after Password Change8.8
The record
- Peak rank
- #179 in Jan 2022
- Busiest month shown
- Jan 2022, 3 CVEs
- Months with a KEV entry
- 0 since Jan 2022
- Monthly snapshots
- 1 since 2022