Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Orchardcore

First CVE: Oct 10, 2021Active for: 5 yearsTotal CVEs: 9

Orchardcore is an open-source content management system and application framework whose vulnerability profile, despite a narrow product scope, ranks among more prominent entities in the landscape due to widespread adoption in web publishing and custom CMS deployments. Vulnerabilities affecting the platform skew toward serious outcomes, concentrating in web-layer input handling and access control, with recurring issues including cross-site scripting, improper authorization, and insufficient session expiration that reflect the authentication and content-rendering demands of a user-facing CMS. Defenders should treat Orchardcore updates as security-relevant, particularly for internet-exposed instances; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Orchardcore over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2021
4 years ago
Most Recent CVE
Nov 25, 2022
1,337 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-37720CRITICAL
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payl
Nov 25, 20229.031NONO
CVE-2021-25966HIGH
In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by t
Oct 10, 20218.828NONO
CVE-2022-0821MEDIUM
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
Mar 11, 20226.523NONO
CVE-2022-0822MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.
Mar 11, 20225.421NONO
CVE-2022-32173MEDIUM
In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into th
Oct 3, 20225.420NONO
CVE-2022-0820MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.
Mar 11, 20226.117NONO
CVE-2022-0243MEDIUM
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.
Jan 19, 20225.415NONO
CVE-2022-0274MEDIUM
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.
Jan 19, 20225.415NONO
CVE-2022-0159MEDIUM
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Jan 12, 20225.415NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
78%
11%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (22.2%)
Unknown0 (0.0%)
Required7 (77.8%)
Privileges Required
Low8 (88.9%)
High0 (0.0%)
None1 (11.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Orchardcore.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Orchardcore — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Orchardcore's Products

View all 3 CNAs →

Top CWEs