Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Orion Platform — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Orion Platform, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration (CWE) related security vulnerabilities affecting the Orion Platform developed by SolarWinds. It aggregates a comprehensive list of disclosed security flaws, ranging from critical remote code execution risks to less severe information disclosure issues. The database covers vulnerabilities reported from the year 2018 through 2023, ensuring a robust historical perspective on the product’s security landscape. By centralizing these data points, the page enables security professionals to efficiently track vendor advisories and correlate them with specific software versions. Users can gain deeper insights into specific weakness classes by observing their manifestation within this particular ecosystem. Furthermore, the repository allows for the detailed examination of a product's vulnerability history, highlighting trends in patching cycles and the frequency of recurring flaw types. This structured approach supports informed risk assessments and facilitates the prioritization of remediation efforts based on historical data and severity classifications. The information serves as a vital resource for administrators seeking to understand past security incidents and apply lessons learned to current configurations. It emphasizes transparency by providing clear mappings between identified weaknesses and the corresponding platform releases. This resource is designed for technical audiences, including security analysts, system administrators, and vulnerability researchers who require precise, actionable data regarding the Orion Platform’s security posture over time.

Vendor: SolarWinds

CVE IDTitleCVSSSeverityPublished
CVE-2022-36965 Stored and DOM XSS in QoE Applications: Orion Platform 6.1 Medium2022-09-30
CVE-2022-36961 Orion Platform SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High2022-09-30
CVE-2021-35244 Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6 6.8 Medium2021-12-20
CVE-2021-35217 Insecure Deserialization of untrusted data causing Remote code execution vulnerability. 8.9 High2021-09-08
CVE-2021-35215 ActionPluginBaseView Deserialization of Untrusted Data RCE CWE-502 8.9 High2021-09-01
CVE-2021-35238 Stored XSS through URL POST parameter in CreateExternalWebsite Vulnerability CWE-79 4.8 Medium2021-09-01
CVE-2021-35212 Blind SQL injection Vulnerability 8.9 High2021-08-31
CVE-2021-35213 Orion User setting Improper Access Control Privilege Escalation Vulnerability CWE-284 8.9 High2021-08-31
CVE-2021-35240 Stored XSS via Help Server settings CWE-79 6.5 Medium2021-08-31
CVE-2021-35239 Stored XSS in Maps text box hyperlink Vulnerability CWE-79 7.5 High2021-08-31
CVE-2021-35222 Resource.aspx Reflected Cross-Site Scripting Vulnerability CWE-79 8.0 High2021-08-31
CVE-2021-35221 ImportAlert Improper Access Control Tampering Vulnerability CWE-284 6.3 Medium2021-08-31
CVE-2021-35220 EmailWebPage Command Injection RCE 8.1 High2021-08-31
CVE-2021-35219 ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability 6.0 Medium2021-08-31
CVE-2021-27258 Solarwinds Orion Platform 安全漏洞 CWE-284 9.8 -2021-04-14
CVE-2020-27871 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 CWE-22 8.8 -2021-02-10
CVE-2020-27870 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 CWE-22 6.5 -2021-02-10
CVE-2020-10148 SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands CWE-288 9.8 -2020-12-29

All 18 known CVE vulnerabilities affecting Orion Platform with full Chinese analysis, references, and POCs where available.