Oroinc's vulnerability footprint centers on a specialized commerce and customer-relationship platform deployed in enterprise and mid-market environments. Its exposure recurs consistently across products including OroPlatform, OroCommerce, and its CRM suite through access-control weaknesses, cross-site scripting, input-handling flaws, and CSRF vectors that are typical of large web applications handling sensitive transactional and customer data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oroinc over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41951CRITICAL OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\Bundle\G | Nov 27, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-43852HIGH OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript langua | Jan 4, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-31037MEDIUM OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclus | Oct 18, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-41236MEDIUM OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS payload added to email template content. An attacker must h | Jan 4, 2022 | 4.8 | 20 | NO | NO |
CVE-2021-39198MEDIUM OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify a | Nov 19, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-50677MEDIUM A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search paramete | Dec 6, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-32065MEDIUM OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is | Nov 28, 2023 | 5.8 | 17 | NO | NO |
CVE-2022-35950MEDIUM OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through 4.2.10, 5.0.0 prior to 5.0.11, and 5.1.0 prior to 5.1.1, th | Oct 9, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-48296MEDIUM OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response | Mar 25, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-32064MEDIUM OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypas | Nov 28, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oroinc.
Media articles that mention a CVE ID that affects a product developed by Oroinc — matched by CVE ID, not by vendor name.