Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Orion Platform — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Orion Platform, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for the Orion Platform, a product developed by the Orion software vendor, classified under the "memory corruption" weakness type. It collects known security defects affecting this specific application across its released versions, covering incidents reported between 2018 and the present. Readers can use this resource to track the vendor's published advisories, understand the characteristics of the memory corruption weakness class, and examine the full vulnerability history associated with the Orion Platform. The data focuses exclusively on confirmed flaws in the platform's codebase, providing a chronological log of identified risks. No specific CVE identifiers are listed here; instead, the page groups entries by date and impact severity. This view supports security teams in assessing exposure and planning remediation strategies for the product.

Vendor: SolarWinds

CVE ID Title CVSS Severity Published
CVE-2022-36965 Stored and DOM XSS in QoE Applications: Orion Platform 6.1 Medium 2022-09-30
CVE-2022-36961 Orion Platform SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High 2022-09-30
CVE-2021-35244 Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6 6.8 Medium 2021-12-20
CVE-2021-35217 Insecure Deserialization of untrusted data causing Remote code execution vulnerability. 8.9 High 2021-09-08
CVE-2021-35215 ActionPluginBaseView Deserialization of Untrusted Data RCE CWE-502 8.9 High 2021-09-01
CVE-2021-35238 Stored XSS through URL POST parameter in CreateExternalWebsite Vulnerability CWE-79 4.8 Medium 2021-09-01
CVE-2021-35212 Blind SQL injection Vulnerability 8.9 High 2021-08-31
CVE-2021-35213 Orion User setting Improper Access Control Privilege Escalation Vulnerability CWE-284 8.9 High 2021-08-31
CVE-2021-35240 Stored XSS via Help Server settings CWE-79 6.5 Medium 2021-08-31
CVE-2021-35239 Stored XSS in Maps text box hyperlink Vulnerability CWE-79 7.5 High 2021-08-31
CVE-2021-35222 Resource.aspx Reflected Cross-Site Scripting Vulnerability CWE-79 8.0 High 2021-08-31
CVE-2021-35221 ImportAlert Improper Access Control Tampering Vulnerability CWE-284 6.3 Medium 2021-08-31
CVE-2021-35220 EmailWebPage Command Injection RCE 8.1 High 2021-08-31
CVE-2021-35219 ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability 6.0 Medium 2021-08-31
CVE-2021-27258 Solarwinds Orion Platform 安全漏洞 CWE-284 9.8 - 2021-04-14
CVE-2020-27871 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 CWE-22 8.8 - 2021-02-10
CVE-2020-27870 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 CWE-22 6.5 - 2021-02-10
CVE-2020-10148 SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands CWE-288 9.8 - 2020-12-29

All 18 known CVE vulnerabilities affecting Orion Platform with full Chinese analysis, references, and POCs where available.