Orchardproject maintains a focused content management system whose vulnerability profile centers on application-layer input-handling defects, particularly cross-site scripting, input validation bypass, and unsafe file upload handling. Treat this as a compact vendor footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orchardproject over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5252MEDIUM Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to red | Jan 12, 2013 | 5.8 | 41 | NO | YES |
CVE-2020-29592CRITICAL An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload allows an attacker to upload dang | Apr 14, 2021 | 9.8 | 29 | NO | NO |
CVE-2015-5520MEDIUM Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML vi | Jul 14, 2015 | 4.3 | 26 | NO | YES |
CVE-2020-29593MEDIUM An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to add a XSS payload that will execute when users attempt to upl | Apr 14, 2021 | 5.4 | 15 | NO | NO |
CVE-2013-3645MEDIUM Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto | Jun 14, 2013 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orchardproject.
Media articles that mention a CVE ID that affects a product developed by Orchardproject — matched by CVE ID, not by vendor name.