CVE-2020-14007: SolarWinds Orion Network Performance Monitor

Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.

Affected products

  • SolarWinds Orion Network Performance Monitor: version 2019.4 only
  • SolarWinds Orion Web Performance Monitor: version 2019.4.1 only

Published 2020-06-24. Last modified 2026-06-17.