High severity8.0NVD Advisory· Published Oct 19, 2020· Updated Jun 17, 2026
CVE-2020-15263
CVE-2020-15263
Description
In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
orchid/platformPackagist | >= 9.0.0, < 9.4.4 | 9.4.4 |
Affected products
3- Range: >= 9.0.0, < 9.4.4
Patches
Vulnerability mechanics
References
4- github.com/orchidsoftware/platform/commit/03f9a113b1a70bc5075ce86a918707f0e7d82169nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-589w-hccm-265xghsaADVISORY
- github.com/orchidsoftware/platform/security/advisories/GHSA-589w-hccm-265xnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15263ghsaADVISORY
News mentions
0No linked articles in our index yet.