Orchardcore is an open-source content management system and application framework whose vulnerability profile, despite a narrow product scope, ranks among more prominent entities in the landscape due to widespread adoption in web publishing and custom CMS deployments. Vulnerabilities affecting the platform skew toward serious outcomes, concentrating in web-layer input handling and access control, with recurring issues including cross-site scripting, improper authorization, and insufficient session expiration that reflect the authentication and content-rendering demands of a user-facing CMS. Defenders should treat Orchardcore updates as security-relevant, particularly for internet-exposed instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orchardcore over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37720CRITICAL Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payl | Nov 25, 2022 | 9.0 | 31 | NO | NO |
CVE-2021-25966HIGH In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by t | Oct 10, 2021 | 8.8 | 28 | NO | NO |
CVE-2022-0821MEDIUM Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0. | Mar 11, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-0822MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0. | Mar 11, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-32173MEDIUM In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into th | Oct 3, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-0820MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0. | Mar 11, 2022 | 6.1 | 17 | NO | NO |
CVE-2022-0243MEDIUM Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2. | Jan 19, 2022 | 5.4 | 15 | NO | NO |
CVE-2022-0274MEDIUM Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2. | Jan 19, 2022 | 5.4 | 15 | NO | NO |
CVE-2022-0159MEDIUM orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Jan 12, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orchardcore.
Media articles that mention a CVE ID that affects a product developed by Orchardcore — matched by CVE ID, not by vendor name.