Total vulnerabilities in the database
OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: