Orientdb

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-25449

    OrientDB 3.0.17 Reflected Cross-Site Scripting via document endpoint

    Last Modified: Apr 07, 2026
    Published: Feb 20, 2026

    CVE-2019-25448

    OrientDB 3.0.17 Stored Cross-Site Scripting via User Creation

    Last Modified: Apr 07, 2026
    Published: Feb 20, 2026

    CVE-2019-25447

    OrientDB 3.0.17 Cross-Site Request Forgery

    Last Modified: Apr 07, 2026
    Published: Feb 20, 2026

    CVE-2017-11467

    OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.

    Last Modified: Apr 20, 2025
    Published: Jul 20, 2017

    CVE-2015-2912

    The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.

    Last Modified: Apr 12, 2025
    Published: Dec 31, 2015
    Items Per Page