CVE-2020-15263: Orchid Platform

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.

Affected products

  • Orchid Platform: from 9.0.0, before 9.4.4 (fixed in 9.4.4)

Published 2020-10-19. Last modified 2026-06-17.