Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 31 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:orangescrum:orangescrum:1.8.0:*:*:*:*:*:*:* |
Fri, 26 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orangescrum
Orangescrum orangescrum |
|
| Vendors & Products |
Orangescrum
Orangescrum orangescrum |
Tue, 23 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints. | |
| Title | Orangescrum 1.8.0 Cross-Site Scripting via Authenticated Endpoints | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:05:39.773Z
Reserved: 2025-12-05T19:10:29.047Z
Link: CVE-2021-47716
Updated: 2025-12-26T13:33:18.597Z
Status : Analyzed
Published: 2025-12-23T20:15:43.377
Modified: 2025-12-31T17:15:17.997
Link: CVE-2021-47716
No data.
OpenCVE Enrichment
Updated: 2025-12-24T11:53:16Z