CVE-2020-37019 MEDIUM

CVE-2020-37019: Orchard Core RC1 - Persistent Cross-Site Scripting

Vendor Orchardcore
Product Orchard Core
Weakness CWE-79 · XSS
Published January 30, 2026
Last update March 5, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.

Key dates

02Disclosure timeline

January 30, 2026 CVE published
March 5, 2026 Record updated

Related vulnerabilities

04Related CVE