Orientdb / OrientDB
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-25449 | OrientDB 3.0.17 Reflected Cross-Site Scripting via document endpoint | MEDIUM | 5.1 | Feb 20, 2026 |
| CVE-2019-25448 | OrientDB 3.0.17 Stored Cross-Site Scripting via User Creation | MEDIUM | 5.1 | Feb 20, 2026 |
| CVE-2019-25447 | OrientDB 3.0.17 Cross-Site Request Forgery | MEDIUM | 5.3 | Feb 20, 2026 |
| CVE-2017-11467 | OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbit… | CRITICAL | 9.8 | Jul 20, 2017 |
| CVE-2015-2918 | The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it… | MEDIUM | 6.1 | Dec 31, 2015 |
| CVE-2015-2913 | server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 imprope… | MEDIUM | 5.9 | Dec 31, 2015 |
| CVE-2015-2912 | The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values… | HIGH | 8.8 | Dec 31, 2015 |
Showing 1 to 7 of 7 CVEs