Skip to main content

Vendor/product archive

orckestra / c1_cms CVEs

Beta · best-effort

4 CVEs tagged to orckestra / c1_cms1 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2022-39256

Published Sep 27, 2022

Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installatio…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24789

Published Mar 28, 2022

C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing t…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34992

Published Nov 15, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required to exploit this vulnerability.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18211

Published Dec 23, 2019

An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1