Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Orientdb

First CVE: Dec 31, 2015Active for: 11 yearsTotal CVEs: 7

OrientDB is a graph and document database platform with a focused product footprint that operates in environments where database compromise can propagate widely across dependent applications. Its vulnerabilities skew toward serious outcomes, frequently acquire public exploit code, and concentrate around web-interface and privilege-management boundaries—specifically CSRF, cross-site scripting, sensitive-information exposure, input validation, and improper access control—reflecting the exposure inherent to a multi-model database with a web-facing administrative layer. Defenders should prioritize network isolation and access controls for this database tier and monitor vendor advisories closely; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Orientdb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2015
10 years ago
Most Recent CVE
Feb 20, 2026
154 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-11467CRITICAL
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via
Jul 20, 20179.884NOYES
CVE-2015-2912HIGH
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote
Dec 31, 20158.822NONO
CVE-2019-25449MEDIUM
OrientDB 3.0.17 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted JSON payloads to the document endpoi
Feb 20, 20266.121NONO
CVE-2019-25448MEDIUM
OrientDB 3.0.17 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating users with script payloads in the n
Feb 20, 20266.421NONO
CVE-2019-25447MEDIUM
OrientDB 3.0.17 GA Community Edition contains cross-site request forgery vulnerabilities that allow attackers to perform unauthorized actions by crafting malicious requests to endp
Feb 20, 20264.317NONO
CVE-2015-2918MEDIUM
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote at
Dec 31, 20156.117NONO
CVE-2015-2913MEDIUM
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the jav
Dec 31, 20155.917NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
71%
14%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Orientdb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Orientdb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Orientdb's Products

View all 3 CNAs →

Top CWEs