📦 Orangehrm

by Orangehrm

🔍 What is Orangehrm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66224

HIGH CVSS 8.8 Nov 29, 2025

OrangeHRM versions 5.0 through 5.7 contain a command injection vulnerability in the mail configuration workflow. Unauthenticated attackers can exploit this to write files to the server and potentially...

CVE-2025-66225

HIGH CVSS 8.8 Nov 29, 2025

This vulnerability allows attackers to reset passwords for any user account in OrangeHRM, including administrative accounts, by exploiting a flaw in the password reset workflow. Attackers need access ...

CVE-2025-66289

HIGH CVSS 8.8 Nov 29, 2025

OrangeHRM versions 5.0 through 5.7 fail to invalidate active user sessions when accounts are disabled or passwords are changed. This allows disabled users or attackers with compromised credentials to ...

CVE-2025-44040

HIGH CVSS 7.2 May 21, 2025

A privilege escalation vulnerability in OrangeHRM v5.7 allows attackers to bypass authentication via PHP loose-equality comparisons if a specific MD5 hash exists in the credential store. This affects ...

CVE-2025-66290

MEDIUM CVSS 4.3 Nov 29, 2025

This vulnerability allows any authenticated user in OrangeHRM to download candidate attachments (CVs, documents) without proper authorization checks. Users with only ESS-level access who shouldn't hav...

CVE-2025-66291

MEDIUM CVSS 4.3 Nov 29, 2025

OrangeHRM versions 5.0 to 5.7 have an authorization bypass vulnerability in the Recruitment module's interview attachment endpoint. Authenticated ESS-level users without recruitment permissions can ac...