Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Orangehrm

First CVE: Mar 2, 2007Active for: 19 yearsTotal CVEs: 31
36.0
VTI Score
Medium

OrangeHRM is a widely deployed human-resources management platform that, despite its narrow product focus, appears in many organizations' business-critical workflows and presents a web-application attack surface. Vulnerabilities affecting the vendor reflect its role as a web-facing application: they concentrate in input-handling and access-control weaknesses, particularly cross-site scripting, SQL injection, path traversal, improper authorization, and exposure of sensitive information. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and appeal of HR systems as targets for credential theft and lateral-movement attacks. Defenders should treat OrangeHRM instances as high-value targets for patching and network segmentation and should monitor this vendor's releases closely; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Orangehrm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2007
19 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1506MEDIUM
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands
Sep 17, 20146.531NOYES
CVE-2025-66224HIGH
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw in its mail configuration and de
Nov 29, 20258.830NONO
CVE-2019-12839HIGH
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbi
Jun 15, 20198.830NONO
CVE-2011-5259MEDIUM
SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Feb 12, 20136.829NOYES
CVE-2010-4798MEDIUM
Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the ur
Apr 27, 20116.829NOYES
CVE-2012-5367MEDIUM
Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sortField parameter to (1) viewCu
Dec 3, 20126.028NOYES
CVE-2012-1507MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plug
Sep 17, 20144.327NOYES
CVE-2025-66289HIGH
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when
Nov 29, 20258.825NONO
CVE-2025-66225HIGH
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final
Nov 29, 20258.825NONO
CVE-2020-29437HIGH
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php lo
Jan 5, 20218.125NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
68%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network21 (67.7%)
Unknown10 (32.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (67.7%)
High0 (0.0%)
Unknown10 (32.3%)
User Interaction
None16 (51.6%)
Unknown10 (32.3%)
Required5 (16.1%)
Privileges Required
Low16 (51.6%)
High4 (12.9%)
None1 (3.2%)
Unknown10 (32.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
19.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Orangehrm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Orangehrm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Orangehrm's Products

View all 2 CNAs →

Top CWEs