OrangeHRM is a widely deployed human-resources management platform that, despite its narrow product focus, appears in many organizations' business-critical workflows and presents a web-application attack surface. Vulnerabilities affecting the vendor reflect its role as a web-facing application: they concentrate in input-handling and access-control weaknesses, particularly cross-site scripting, SQL injection, path traversal, improper authorization, and exposure of sensitive information. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and appeal of HR systems as targets for credential theft and lateral-movement attacks. Defenders should treat OrangeHRM instances as high-value targets for patching and network segmentation and should monitor this vendor's releases closely; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orangehrm over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1506MEDIUM SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands | Sep 17, 2014 | 6.5 | 31 | NO | YES |
CVE-2025-66224HIGH OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw in its mail configuration and de | Nov 29, 2025 | 8.8 | 30 | NO | NO |
CVE-2019-12839HIGH In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbi | Jun 15, 2019 | 8.8 | 30 | NO | NO |
CVE-2011-5259MEDIUM SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 12, 2013 | 6.8 | 29 | NO | YES |
CVE-2010-4798MEDIUM Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the ur | Apr 27, 2011 | 6.8 | 29 | NO | YES |
CVE-2012-5367MEDIUM Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sortField parameter to (1) viewCu | Dec 3, 2012 | 6.0 | 28 | NO | YES |
CVE-2012-1507MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plug | Sep 17, 2014 | 4.3 | 27 | NO | YES |
CVE-2025-66289HIGH OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when | Nov 29, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-66225HIGH OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final | Nov 29, 2025 | 8.8 | 25 | NO | NO |
CVE-2020-29437HIGH SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php lo | Jan 5, 2021 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orangehrm.
Media articles that mention a CVE ID that affects a product developed by Orangehrm — matched by CVE ID, not by vendor name.