Solarwinds Platform
by SolarWinds
CVEs (48)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35228 | Med | 0.36 | 5.5 | 0.01 | Oct 21, 2021 | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change… | ||
| CVE-2025-26391 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2025 | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. | ||
| CVE-2022-36966 | Med | 0.35 | 5.4 | 0.00 | Oct 20, 2022 | Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous. | ||
| CVE-2024-45714 | Med | 0.31 | 4.8 | 0.01 | Oct 16, 2024 | Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload. | ||
| CVE-2023-3622 | Med | 0.28 | 4.3 | 0.01 | Jul 26, 2023 | Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource | ||
| CVE-2024-52611 | Low | 0.23 | 3.5 | 0.00 | Feb 11, 2025 | The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions. | ||
| CVE-2024-52606 | Low | 0.23 | 3.5 | 0.02 | Feb 11, 2025 | SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request. | ||
| CVE-2023-33229 | Low | 0.23 | 3.5 | 0.01 | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML. |
- risk 0.36cvss 5.5epss 0.01
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change…
- risk 0.35cvss 5.4epss 0.00
SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
- risk 0.35cvss 5.4epss 0.00
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.
- risk 0.31cvss 4.8epss 0.01
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
- risk 0.28cvss 4.3epss 0.01
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
- risk 0.23cvss 3.5epss 0.00
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions.
- risk 0.23cvss 3.5epss 0.02
SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request.
- risk 0.23cvss 3.5epss 0.01
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML.
Page 3 of 3