Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orchardcore
Orchardcore orchard Core |
|
| Vendors & Products |
Orchardcore
Orchardcore orchard Core |
Fri, 30 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers. | |
| Title | Orchard Core RC1 - Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-30T16:16:39.149Z
Updated: 2026-01-30T16:32:21.964Z
Reserved: 2026-01-28T18:18:30.522Z
Link: CVE-2020-37019
Updated: 2026-01-30T16:32:19.087Z
Status : Awaiting Analysis
Published: 2026-01-30T17:16:11.333
Modified: 2026-02-04T16:34:21.763
Link: CVE-2020-37019
No data.