Orionserver develops a focused application server product with a modestly tracked vulnerability footprint centered on web-request handling weaknesses, particularly cross-site scripting flaws. Treat this as a compact vendor profile rather than a broad industry trend; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orionserver over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0816MEDIUM Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the exten | Mar 24, 2006 | 5.0 | 15 | NO | NO |
CVE-2002-1859MEDIUM Orion Application Server 1.5.3, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration infor | Dec 31, 2002 | 5.0 | 15 | NO | NO |
CVE-2005-2981MEDIUM Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the re | Sep 20, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orionserver.
Media articles that mention a CVE ID that affects a product developed by Orionserver — matched by CVE ID, not by vendor name.