VYPR

Orchardcore

by Orchardproject

nuget: orchardcore

Source repositories

CVEs (8)

  • CVE-2021-25966HigOct 10, 2021
    risk 0.57cvss 8.8epss 0.01

    In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to…

  • CVE-2020-37019MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary…

  • CVE-2022-0274MedJan 19, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.

  • CVE-2022-0159MedJan 12, 2022
    risk 0.28cvss 5.4epss 0.01

    orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2022-0822MedMar 11, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0821MedMar 11, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0820MedMar 11, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0243MedJan 19, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.