CVE-2020-29593: Orchardproject Orchard

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to add a XSS payload that will execute when users attempt to upload a disallowed file type, causing the error to display.

Affected products

Published 2021-04-14. Last modified 2026-06-17.