GHSA-gfhp-jgp6-838j · Severity: critical · Ecosystem: nuget — Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. This issue is patched in C1 CMS v6.13. There are no known workarounds.
Conclusion & alert: CVE-2022-39256 is rated Moderate Risk (57.4/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.18%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.07% | 1.18% | -0.88% |
| 2 | 2025-10-03 | 2.35% | 2.07% | -0.29% |
| 3 | 2025-09-30 | — | 2.35% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
| 8.0 | 3.1 | HIGH |
|
2.1 | 5.9 | [email protected] |
GHSA-gfhp-jgp6-838j · Severity: critical · Ecosystem: nuget — Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
| URL | Tags |
|---|---|
| https://github.com/Orckestra/C1-CMS-Foundation/pull/814 | Patch Third Party Advisory |
| https://github.com/Orckestra/C1-CMS-Foundation/releases/tag/v6.13 | Release Notes Third Party Advisory |
| https://github.com/Orckestra/C1-CMS-Foundation/security/advisories/GHSA-gfhp-jgp6-838j | Third Party Advisory |