Orangescrum is a project-management and collaboration platform whose vulnerability profile concentrates in a single application and clusters around web-application input-handling and access-control issues, including cross-site scripting, path traversal, OS command injection, SQL injection, and authorization bypass through user-controlled keys. These weakness classes reflect the application's role as a web-facing, database-backed system requiring robust input validation and privilege enforcement. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orangescrum over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-47721HIGH Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attack | Dec 23, 2025 | 8.8 | 28 | NO | NO |
CVE-2023-0454HIGH OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized a | Feb 1, 2023 | 8.1 | 26 | NO | NO |
CVE-2023-1783HIGH OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML con | Jun 23, 2023 | 7.6 | 23 | NO | NO |
CVE-2023-0164HIGH OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-contr | Jan 18, 2023 | 8.8 | 22 | NO | NO |
CVE-2021-47720HIGH Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attacker | Dec 23, 2025 | 7.1 | 21 | NO | NO |
CVE-2023-0738MEDIUM OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input | Apr 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-0624MEDIUM OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input | Feb 9, 2023 | 6.1 | 20 | NO | NO |
CVE-2021-47716MEDIUM Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers | Dec 23, 2025 | 5.4 | 19 | NO | NO |
CVE-2024-48392MEDIUM OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead | Jan 21, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orangescrum.
Media articles that mention a CVE ID that affects a product developed by Orangescrum — matched by CVE ID, not by vendor name.