Organizr is a self-hosted dashboard and media-server orchestration application that concentrates its vulnerability exposure in a single, narrowly scoped product serving a niche but prominent deployment footprint. The recurring weakness classes—cross-site scripting, SQL injection, and integer-overflow conditions—reflect the classic input-handling and validation risks endemic to web applications that aggregate and proxy access to multiple backend services. Vulnerabilities affecting this vendor skew toward critical severity, consistent with the product's trusted, admin-facing role in home-lab and small-organization environments where authentication bypass or code execution carries high impact. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Organizr over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41370CRITICAL Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php. | Aug 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-41372CRITICAL Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php. | Aug 29, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-1347HIGH Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover an | Apr 13, 2022 | 8.4 | 28 | NO | NO |
CVE-2022-1699HIGH Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not | May 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-1345CRITICAL Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead t | Apr 13, 2022 | 9.0 | 22 | NO | NO |
CVE-2022-1346CRITICAL Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hij | Apr 13, 2022 | 9.0 | 22 | NO | NO |
CVE-2022-1344CRITICAL Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser | Apr 13, 2022 | 9.0 | 22 | NO | NO |
CVE-2022-1909MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200. | May 27, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-1698HIGH Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine | May 12, 2022 | 7.5 | 19 | NO | NO |
CVE-2024-41371MEDIUM Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php. | Aug 29, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Organizr.
Media articles that mention a CVE ID that affects a product developed by Organizr — matched by CVE ID, not by vendor name.