Vulnerabilities (CVE)

Filtered by vendor Orangehrm Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28985 1 Orangehrm 1 Orangehrm 2022-05-26 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
CVE-2021-28399 1 Orangehrm 1 Orangehrm 2021-05-05 5.0 MEDIUM 5.3 MEDIUM
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.
CVE-2013-1353 1 Orangehrm 1 Orangehrm 2020-02-11 3.5 LOW 5.4 MEDIUM
Orange HRM 2.7.1 allows XSS via the vacancy name.