Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oroinc

First CVE: Nov 19, 2021Active for: 5 yearsTotal CVEs: 13
11.9
VTI Score
Low

Oroinc's vulnerability footprint centers on a specialized commerce and customer-relationship platform deployed in enterprise and mid-market environments. Its exposure recurs consistently across products including OroPlatform, OroCommerce, and its CRM suite through access-control weaknesses, cross-site scripting, input-handling flaws, and CSRF vectors that are typical of large web applications handling sensitive transactional and customer data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oroinc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2021
4 years ago
Most Recent CVE
Dec 6, 2024
595 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-41951CRITICAL
OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\Bundle\G
Nov 27, 20239.829NONO
CVE-2021-43852HIGH
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript langua
Jan 4, 20228.828NONO
CVE-2022-31037MEDIUM
OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclus
Oct 18, 20225.420NONO
CVE-2021-41236MEDIUM
OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS payload added to email template content. An attacker must h
Jan 4, 20224.820NONO
CVE-2021-39198MEDIUM
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify a
Nov 19, 20215.420NONO
CVE-2024-50677MEDIUM
A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search paramete
Dec 6, 20246.118NONO
CVE-2023-32065MEDIUM
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is
Nov 28, 20235.817NONO
CVE-2022-35950MEDIUM
OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through 4.2.10, 5.0.0 prior to 5.0.11, and 5.1.0 prior to 5.1.1, th
Oct 9, 20234.817NONO
CVE-2023-48296MEDIUM
OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response
Mar 25, 20244.316NONO
CVE-2023-32064MEDIUM
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypas
Nov 28, 20234.316NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
85%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low6 (46.2%)
High2 (15.4%)
None5 (38.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oroinc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oroinc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oroinc's Products

View all 2 CNAs →

Top CWEs