Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Orangescrum

First CVE: Jan 18, 2023Active for: 4 yearsTotal CVEs: 9

Orangescrum is a project-management and collaboration platform whose vulnerability profile concentrates in a single application and clusters around web-application input-handling and access-control issues, including cross-site scripting, path traversal, OS command injection, SQL injection, and authorization bypass through user-controlled keys. These weakness classes reflect the application's role as a web-facing, database-backed system requiring robust input validation and privilege enforcement. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Orangescrum over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2023
3 years ago
Most Recent CVE
Dec 23, 2025
213 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-47721HIGH
Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attack
Dec 23, 20258.828NONO
CVE-2023-0454HIGH
OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized a
Feb 1, 20238.126NONO
CVE-2023-1783HIGH
OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML con
Jun 23, 20237.623NONO
CVE-2023-0164HIGH
OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-contr
Jan 18, 20238.822NONO
CVE-2021-47720HIGH
Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attacker
Dec 23, 20257.121NONO
CVE-2023-0738MEDIUM
OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input
Apr 4, 20236.121NONO
CVE-2023-0624MEDIUM
OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input
Feb 9, 20236.120NONO
CVE-2021-47716MEDIUM
Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers
Dec 23, 20255.419NONO
CVE-2024-48392MEDIUM
OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead
Jan 21, 20255.417NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
56%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (44.4%)
Unknown0 (0.0%)
Required5 (55.6%)
Privileges Required
Low7 (77.8%)
High0 (0.0%)
None2 (22.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Orangescrum.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Orangescrum — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Orangescrum's Products

View all 3 CNAs →

Top CWEs