CVE-2020-29593: Orchardproject Orchard
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to add a XSS payload that will execute when users attempt to upload a disallowed file type, causing the error to display.
Affected products
- Orchardproject Orchard: before 1.10 (fixed in 1.10)
Published 2021-04-14. Last modified 2026-06-17.