OrientDB is a graph and document database platform with a focused product footprint that operates in environments where database compromise can propagate widely across dependent applications. Its vulnerabilities skew toward serious outcomes, frequently acquire public exploit code, and concentrate around web-interface and privilege-management boundaries—specifically CSRF, cross-site scripting, sensitive-information exposure, input validation, and improper access control—reflecting the exposure inherent to a multi-model database with a web-facing administrative layer. Defenders should prioritize network isolation and access controls for this database tier and monitor vendor advisories closely; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orientdb over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11467CRITICAL OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via | Jul 20, 2017 | 9.8 | 84 | NO | YES |
CVE-2015-2912HIGH The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote | Dec 31, 2015 | 8.8 | 22 | NO | NO |
CVE-2019-25449MEDIUM OrientDB 3.0.17 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted JSON payloads to the document endpoi | Feb 20, 2026 | 6.1 | 21 | NO | NO |
CVE-2019-25448MEDIUM OrientDB 3.0.17 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating users with script payloads in the n | Feb 20, 2026 | 6.4 | 21 | NO | NO |
CVE-2019-25447MEDIUM OrientDB 3.0.17 GA Community Edition contains cross-site request forgery vulnerabilities that allow attackers to perform unauthorized actions by crafting malicious requests to endp | Feb 20, 2026 | 4.3 | 17 | NO | NO |
CVE-2015-2918MEDIUM The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote at | Dec 31, 2015 | 6.1 | 17 | NO | NO |
CVE-2015-2913MEDIUM server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the jav | Dec 31, 2015 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orientdb.
Media articles that mention a CVE ID that affects a product developed by Orientdb — matched by CVE ID, not by vendor name.