Orckestra's vulnerability footprint centers on its C1 CMS platform, a content-management system where disclosed weaknesses concentrate around deserialization of untrusted data and server-side request forgery, reflecting the risks of user-supplied content handling and inter-service communication in web platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orckestra over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34992HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required to exploit this vulnerability. T | Nov 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2019-18211HIGH An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payload | Dec 23, 2019 | 8.8 | 27 | NO | NO |
CVE-2022-39256HIGH Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installation | Sep 27, 2022 | 8.0 | 26 | NO | NO |
CVE-2022-24789HIGH C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing th | Mar 28, 2022 | 7.6 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orckestra.
Media articles that mention a CVE ID that affects a product developed by Orckestra — matched by CVE ID, not by vendor name.