CVE-2021-35239: SolarWinds Orion Platform

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.

Affected products

  • SolarWinds Orion Platform: up to and including 2020.2.5; version 2020.2.6 only

Published 2021-08-31. Last modified 2026-06-17.