MEDIUM
Orchard Core RC1 - Persistent Cross-Site Scripting
Published Jan 30, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.46%
Description
Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Orchardcore | Orchard Core | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://www.orchardcore.net/ product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30959 Advisory
- https://github.com/OrchardCMS/OrchardCore product
- https://github.com/OrchardCMS/OrchardCore/issues/5802 issue-tracking
- https://www.exploit-db.com/exploits/48456 exploit
- https://www.vulncheck.com/advisories/orchard-core-rc-persistent-cross-site-scripting third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.orchardcore.net/ | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30959 | Advisory | |
| https://github.com/OrchardCMS/OrchardCore | product | |
| https://github.com/OrchardCMS/OrchardCore/issues/5802 | issue-tracking | |
| https://www.exploit-db.com/exploits/48456 | exploit | |
| https://www.vulncheck.com/advisories/orchard-core-rc-persistent-cross-site-scripting | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jan 30, 2026
Updated Jun 23, 2026
Reserved Jan 28, 2026
Link CVE-2020-37019
CISA Vulnrichment
Updated Jan 30, 2026
ENISA EUVD
EUVD-2020-30959 Assigner VulnCheck
Published Jan 30, 2026
Updated Jun 23, 2026
Exploited since n/a
Link EUVD-2020-30959