OrchardCore
Orchard Core Framework is an application framework for building modular, multi-tenant applications on ASP.NET Core. Implementation of OrchardCore modular, multi-tenant ShellHost
Activity
- Latest release
- 2mo ago
- Total releases
- 38
- Cadence
- ~37 days
- Last 12 months
- 3
Details
- License
- BSD-3-Clause
- First release
- Apr 03, 2019
| Version | Released | |
|---|---|---|
3.0.1
patch
|
3.0.1
patch
Dependencies (11)
+ 3 more |
|
3.0.0
major
|
3.0.0
major
Dependencies (11)
+ 3 more |
|
2.2.1
patch
|
2.2.1
patch
Dependencies (8)
|
|
2.2.0
minor
|
2.2.0
minor
Dependencies (8)
|
|
2.1.9
patch
|
2.1.9
patch
Dependencies (8)
|
|
2.1.8
patch
|
2.1.8
patch
Dependencies (8)
|
|
2.1.7
patch
|
2.1.7
patch
Dependencies (8)
|
|
2.1.6
patch
|
2.1.6
patch
Dependencies (8)
|
|
2.1.5
patch
|
2.1.5
patch
Dependencies (8)
|
|
2.1.4
patch
|
2.1.4
patch
Dependencies (8)
|
|
2.1.3
patch
|
2.1.3
patch
Dependencies (8)
|
|
2.1.2
patch
|
2.1.2
patch
Dependencies (8)
|
|
2.1.1
patch
|
2.1.1
patch
Dependencies (8)
|
|
2.1.0
minor
|
2.1.0
minor
Dependencies (8)
|
|
2.0.2
patch
|
2.0.2
patch
Dependencies (7)
|
|
2.0.1
patch
|
2.0.1
patch
Dependencies (7)
|
|
2.0.0
major
|
2.0.0
major
Dependencies (7)
|
|
1.8.4
patch
|
1.8.4
patch
Dependencies (5)
|
|
1.8.3
patch
|
1.8.3
patch
Dependencies (5)
|
|
1.8.2
patch
|
1.8.2
patch
Dependencies (5)
|
|
1.8.1
patch
|
1.8.1
patch
Dependencies (5)
|
|
1.8.0
minor
|
1.8.0
minor
Dependencies (5)
|
|
1.7.2
patch
|
1.7.2
patch
Dependencies (5)
|
|
1.7.1
patch
|
1.7.1
patch
Dependencies (5)
|
|
1.7.0
minor
|
1.7.0
minor
Dependencies (5)
|
|
1.6.0
minor
|
1.6.0
minor
Dependencies (5)
|
|
1.5.0
minor
|
1.5.0
minor
Dependencies (5)
|
|
1.4.0
minor
|
1.4.0
minor
Dependencies (5)
|
|
1.3.0
minor
1 CVE
CVE-2022-32173
GHSA-5gg9-gwj4-mqmj
Oct 04, 2022
OrchardCore vulnerable to HTML injection
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch. Affected versions
1.0.0
1.0.0-rc2-13450
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
Fixed in
1.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.3.0
minor
Dependencies (5)
|
|
1.2.2
patch
1 CVE
CVE-2022-32173
GHSA-5gg9-gwj4-mqmj
Oct 04, 2022
OrchardCore vulnerable to HTML injection
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch. Affected versions
1.0.0
1.0.0-rc2-13450
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
Fixed in
1.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.2.2
patch
Dependencies (5)
|
|
1.2.1
patch
1 CVE
CVE-2022-32173
GHSA-5gg9-gwj4-mqmj
Oct 04, 2022
OrchardCore vulnerable to HTML injection
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch. Affected versions
1.0.0
1.0.0-rc2-13450
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
Fixed in
1.4.0
References Updated Nov 08, 2023 · Source: OSV.dev |
1.2.1
patch
Dependencies (5)
|
|
1.2.0
minor
2 CVEs
CVE-2022-32173
GHSA-5gg9-gwj4-mqmj
Oct 04, 2022
OrchardCore vulnerable to HTML injection
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch. Affected versions
1.0.0
1.0.0-rc2-13450
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
Fixed in
1.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-0159
GHSA-6w5m-jgc5-8cgc
Jan 21, 2022
orchardcore is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
1.0.0
1.0.0-beta3-71075
1.0.0-beta3-71077
1.0.0-rc1-10004
1.0.0-rc2-13450
1.1.0
1.2.0
Fixed in
1.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |
1.2.0
minor
Dependencies (5)
|
|
1.1.0
minor
2 CVEs
CVE-2022-32173
GHSA-5gg9-gwj4-mqmj
Oct 04, 2022
OrchardCore vulnerable to HTML injection
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch. Affected versions
1.0.0
1.0.0-rc2-13450
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
Fixed in
1.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-0159
GHSA-6w5m-jgc5-8cgc
Jan 21, 2022
orchardcore is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
1.0.0
1.0.0-beta3-71075
1.0.0-beta3-71077
1.0.0-rc1-10004
1.0.0-rc2-13450
1.1.0
1.2.0
Fixed in
1.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.0
minor
Dependencies (5)
|
|
1.0.0
initial
2 CVEs
CVE-2022-32173
GHSA-5gg9-gwj4-mqmj
Oct 04, 2022
OrchardCore vulnerable to HTML injection
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch. Affected versions
1.0.0
1.0.0-rc2-13450
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
Fixed in
1.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-0159
GHSA-6w5m-jgc5-8cgc
Jan 21, 2022
orchardcore is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
1.0.0
1.0.0-beta3-71075
1.0.0-beta3-71077
1.0.0-rc1-10004
1.0.0-rc2-13450
1.1.0
1.2.0
Fixed in
1.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0
initial
Dependencies (5)
|
|
1.0.0-rc2-13450
pre
2 CVEs
CVE-2022-32173
GHSA-5gg9-gwj4-mqmj
Oct 04, 2022
OrchardCore vulnerable to HTML injection
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch. Affected versions
1.0.0
1.0.0-rc2-13450
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
Fixed in
1.4.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-0159
GHSA-6w5m-jgc5-8cgc
Jan 21, 2022
orchardcore is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
1.0.0
1.0.0-beta3-71075
1.0.0-beta3-71077
1.0.0-rc1-10004
1.0.0-rc2-13450
1.1.0
1.2.0
Fixed in
1.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0-rc2-13450
pre
Dependencies (4)
|
|
1.0.0-rc1-10004
pre
1 CVE
CVE-2022-0159
GHSA-6w5m-jgc5-8cgc
Jan 21, 2022
orchardcore is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
1.0.0
1.0.0-beta3-71075
1.0.0-beta3-71077
1.0.0-rc1-10004
1.0.0-rc2-13450
1.1.0
1.2.0
Fixed in
1.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0-rc1-10004
pre
Dependencies (4)
|
|
1.0.0-beta3-71077
pre
1 CVE
CVE-2022-0159
GHSA-6w5m-jgc5-8cgc
Jan 21, 2022
orchardcore is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
1.0.0
1.0.0-beta3-71075
1.0.0-beta3-71077
1.0.0-rc1-10004
1.0.0-rc2-13450
1.1.0
1.2.0
Fixed in
1.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0-beta3-71077
pre
Dependencies (21)
+ 13 more |
|
1.0.0-beta3-71075
pre
1 CVE
CVE-2022-0159
GHSA-6w5m-jgc5-8cgc
Jan 21, 2022
orchardcore is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
1.0.0
1.0.0-beta3-71075
1.0.0-beta3-71077
1.0.0-rc1-10004
1.0.0-rc2-13450
1.1.0
1.2.0
Fixed in
1.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0-beta3-71075
pre
Dependencies (21)
+ 13 more |