Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Orion Platform — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Orion Platform, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized vulnerability aggregation hub for the Orion Platform, focusing on security weaknesses associated with this specific network management solution. It systematically collects data on known flaws, misconfigurations, and exploit-related incidents affecting the vendor’s software ecosystem. The content aggregates information from diverse sources, covering a broad historical time range that extends from early product versions to recent updates, ensuring comprehensive visibility into past and present security issues. Users navigating this resource can efficiently track vendor advisories and security bulletins issued by the software provider, allowing them to stay informed about patch releases and remediation strategies. The platform enables a deep understanding of specific weakness classes, such as buffer overflows, injection flaws, or privilege escalation mechanisms, by providing contextual details and severity ratings for each reported issue. Additionally, users can look up a product's vulnerability history to analyze trends, assess risk exposure over time, and prioritize mitigation efforts based on historical data. This structured approach helps security professionals and administrators evaluate the security posture of the Orion Platform effectively. By consolidating fragmented reports into a single view, the page facilitates quicker decision-making regarding upgrades, configuration changes, and defensive measures. The goal is to provide a clear, factual reference point for understanding the security landscape of the Orion Platform without unnecessary noise or outdated information, supporting proactive security management and compliance requirements.

Vendor: SolarWinds

CVE IDTitleCVSSSeverityPublished
CVE-2022-36965 Stored and DOM XSS in QoE Applications: Orion Platform 6.1 Medium2022-09-30
CVE-2022-36961 Orion Platform SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High2022-09-30
CVE-2021-35244 Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6 6.8 Medium2021-12-20
CVE-2021-35217 Insecure Deserialization of untrusted data causing Remote code execution vulnerability. 8.9 High2021-09-08
CVE-2021-35215 ActionPluginBaseView Deserialization of Untrusted Data RCE CWE-502 8.9 High2021-09-01
CVE-2021-35238 Stored XSS through URL POST parameter in CreateExternalWebsite Vulnerability CWE-79 4.8 Medium2021-09-01
CVE-2021-35212 Blind SQL injection Vulnerability 8.9 High2021-08-31
CVE-2021-35213 Orion User setting Improper Access Control Privilege Escalation Vulnerability CWE-284 8.9 High2021-08-31
CVE-2021-35240 Stored XSS via Help Server settings CWE-79 6.5 Medium2021-08-31
CVE-2021-35239 Stored XSS in Maps text box hyperlink Vulnerability CWE-79 7.5 High2021-08-31
CVE-2021-35222 Resource.aspx Reflected Cross-Site Scripting Vulnerability CWE-79 8.0 High2021-08-31
CVE-2021-35221 ImportAlert Improper Access Control Tampering Vulnerability CWE-284 6.3 Medium2021-08-31
CVE-2021-35220 EmailWebPage Command Injection RCE 8.1 High2021-08-31
CVE-2021-35219 ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability 6.0 Medium2021-08-31
CVE-2021-27258 Solarwinds Orion Platform 安全漏洞 CWE-284 9.8 -2021-04-14
CVE-2020-27871 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 CWE-22 8.8 -2021-02-10
CVE-2020-27870 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 CWE-22 6.5 -2021-02-10
CVE-2020-10148 SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands CWE-288 9.8 -2020-12-29

All 18 known CVE vulnerabilities affecting Orion Platform with full Chinese analysis, references, and POCs where available.