Orchid's vulnerability footprint centers on its platform product, a narrowly scoped but above-typical presence in the landscape, with the durable signal rooted in application-layer handling of untrusted data—including deserialization flaws and cross-site scripting weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orchid over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36825CRITICAL Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-a | Jul 11, 2023 | 9.8 | 27 | NO | NO |
CVE-2020-15263MEDIUM In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was | Oct 19, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orchid.
Media articles that mention a CVE ID that affects a product developed by Orchid — matched by CVE ID, not by vendor name.