Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

platform — Vulnerabilities & Security Advisories 61

All 61 CVE vulnerabilities found in platform, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security vulnerabilities related to the platform product. It serves as a centralized resource for tracking security weaknesses, vendor advisories, and historical incident data associated with this specific software ecosystem. The collection focuses on identifying, categorizing, and documenting security flaws that may impact the integrity, confidentiality, or availability of the platform infrastructure. The vulnerability database on this page covers a wide spectrum of issue types, including but not limited to injection flaws, broken access control, security misconfigurations, and cross-site scripting. The data encompasses records spanning the last three years, ensuring that both legacy and recent security concerns are accessible for analysis. This timeframe allows users to observe trends in vulnerability disclosure and patch adoption over time. Visitors can use this resource to track specific vendor advisories and understand the context of each weakness class within the platform environment. By examining the detailed history of vulnerabilities, stakeholders can assess the overall security posture of the product and identify patterns in reported issues. This information supports informed decision-making regarding system updates, remediation efforts, and risk management strategies. The aggregated data is structured to facilitate efficient searching and filtering by severity, status, and publication date, enabling security professionals to conduct thorough due diligence and maintain robust security practices for the platform.

Vendor: orchidsoftware

CVE ID Title CVSS Severity Published
CVE-2023-45824 OroPlatform's pinned entity creation form shows pages of other users CWE-200 4.3 Medium 2024-03-25
CVE-2022-41951 OroPlatform vulnerable to path traversal during temporary file manipulations CWE-22 8.6 High 2023-11-27
CVE-2023-5964 1E-Exchange-DisplayMessage instruction allows for arbitrary code execution CWE-20 9.9 Critical 2023-11-06
CVE-2023-45163 1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution CWE-20 9.9 Critical 2023-11-06
CVE-2023-45161 1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution CWE-20 9.9 Critical 2023-11-06
CVE-2023-36825 Orchid Deserialization of Untrusted Data vulnerability leads to Remote Code Execution CWE-502 9.7 Critical 2023-07-11
CVE-2023-22733 Improper Output Neutralization in Log Module in shopware CWE-532 2.7 Low 2023-01-17
CVE-2023-22732 Insufficient Session Expiration in Administration in shopware CWE-613 3.7 Low 2023-01-17
CVE-2023-22731 Improper Control of Generation of Code in Twig rendered views in shopware CWE-94 10.0 Critical 2023-01-17
CVE-2023-22730 Improper Input Validation of Clearance sale in cart CWE-20 5.3 Medium 2023-01-17
CVE-2023-22734 Improper Input Newsletter subscription option validation in shopware CWE-20 4.3 Medium 2023-01-17
CVE-2022-24872 Improper Access Control in shopware CWE-732 8.1 High 2022-04-20
CVE-2022-24871 Server-Side Request Forgery (SSRF) in Shopware CWE-918 7.2 High 2022-04-20
CVE-2022-24744 Insufficient Session Expiration in shopware CWE-613 2.6 Low 2022-03-09
CVE-2022-24745 Guest session is shared between customers in shopware CWE-384 4.8 Medium 2022-03-09
CVE-2022-24746 HTML injection possibility in voucher code form CWE-79 6.1 Medium 2022-03-09
CVE-2022-24747 HTTP caching is marking private HTTP headers as public CWE-200 6.3 Medium 2022-03-09
CVE-2022-24748 Incorrect Authentication in shopware CWE-287 6.8 Medium 2022-03-09
CVE-2021-43852 JavaScript Prototype Pollution in oro/platform CWE-74 8.8 High 2022-01-04
CVE-2021-41236 XSS vulnerability in oro/platform CWE-79 6.9 Medium 2022-01-04
CVE-2021-37711 Authenticated server-side request forgery in file upload via URL. CWE-918 8.8 High 2021-08-16
CVE-2021-37710 Cross-Site Scripting via SVG media files CWE-79 8.0 High 2021-08-16
CVE-2021-37709 Insecure direct object reference of log files of the Import/Export feature CWE-532 6.5 Medium 2021-08-16
CVE-2021-37708 Command injection in mail agent settings CWE-77 8.8 High 2021-08-16
CVE-2021-37707 Manipulation of product reviews via API CWE-20 6.5 Medium 2021-08-16
CVE-2021-32717 Private files publicly accessible with Cloud Storage providers CWE-200 7.5 High 2021-06-24
CVE-2021-32716 Internal hidden fields are visible on to many associations in admin api CWE-200 4.4 Medium 2021-06-24
CVE-2021-32711 Leak of information via Store-API CWE-200 9.1 Critical 2021-06-24
CVE-2021-32710 Potential Session Hijacking in Shopware CWE-384 5.9 Medium 2021-06-24
CVE-2021-32709 Creation of order credits was not validated by acl in admin orders CWE-306 4.9 Medium 2021-06-24

All 61 known CVE vulnerabilities affecting platform with full Chinese analysis, references, and POCs where available.