VYPR

Solarwinds Platform

by SolarWinds

CVEs (48)

  • CVE-2021-35228MedOct 21, 2021
    risk 0.36cvss 5.5epss 0.01

    This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change…

  • CVE-2025-26391MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.

  • CVE-2022-36966MedOct 20, 2022
    risk 0.35cvss 5.4epss 0.00

    Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

  • CVE-2024-45714MedOct 16, 2024
    risk 0.31cvss 4.8epss 0.01

    Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

  • CVE-2023-3622MedJul 26, 2023
    risk 0.28cvss 4.3epss 0.01

    Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource

  • CVE-2024-52611LowFeb 11, 2025
    risk 0.23cvss 3.5epss 0.00

    The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions.

  • CVE-2024-52606LowFeb 11, 2025
    risk 0.23cvss 3.5epss 0.02

    SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request.

  • CVE-2023-33229LowJul 26, 2023
    risk 0.23cvss 3.5epss 0.01

    The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML.

Page 3 of 3