Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-37720: Orchard | Buy your next home before you sell

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim’s browser.

CVE
#xss#java#auth

Get the most accurate free home valuation in minutes

Orchard is 30% more accurate than the rest.

FEATURED IN

The Modern Way
to Buy****Orchard makes home buying stress-free. Never miss out on a great home because you haven’t sold your current one.

Become a Cash Buyer

Leave the bidding wars behind. Stand out to sellers and win your next home with an all-cash offer.

Unlock Your Equity

Gain access to your hard-earned home equity. We can help you unlock your home value upfront, even before you list.

Skip the Showings

Find your next home without rushing to sell first. After you move in, we’ll handle listing and showing your old home while you relax and enjoy your new one.

Get Expert Home Prep

Skip the do-it-yourself repairs. We make value-boosting updates and get your home list-ready with no upfront cost or interest.

Move Once

With Orchard, you move into your new home without having to sell your current home first. No rentals, no double moves.

The First Step is a Breeze

We’ll ask you a few questions about your goals so that we can match you with the best service.

Get Started

See Our Services for more info

There’s No Comparison****Why choose between friendly service, a convenient sale, and the highest price for your home? Orchard gets you all three for a comparable fee to traditional agents.

Compare:

Traditional Agents

expand_more

vs

Traditional Agents

Homebuying Companies

Become a cash buyer

Buy before you sell

Licensed real estate agent

List for top dollar

Guaranteed home sale

Option to skip home showings

Don’t Take it
From Us****Discover real customer stories.

play_arrow

play_arrow

Start Browsing Homes

Let us find you the perfect next home or just start window shopping.

Related news

CVE-2022-46496: CVE-2022-46496 - Missing TLS Certificate Validation in DoorEntry HOMETOUCH for iOS

BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907