Orckestra

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-39256

    Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.

    Last Modified: Apr 23, 2025
    Published: Sep 27, 2022

    CVE-2022-24789

    Deserialization of untrusted data in C1 CMS.

    Last Modified: Apr 23, 2025
    Published: Mar 28, 2022

    CVE-2021-34992

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required to exploit this vulnerability. The specific flaw exists within Composite.dll. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-14740.

    Last Modified: Nov 21, 2024
    Published: Nov 15, 2021

    CVE-2019-18211

    An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code execution for any low-privilege user.

    Last Modified: Nov 21, 2024
    Published: Dec 23, 2019
    Items Per Page
    Orckestra Vulnerabilities & Security CVEs | CVE-DB