Known Vulnerabilities for MiniOrange 2FA by Unknown
Listed below are 9 of the newest known vulnerabilities associated with "MiniOrange 2FA" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61957 json | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59545 json | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-57807 json | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single ... | Not Provided | 2026-07-10 | 2026-07-21 |
| CVE-2026-42731 json | Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Pri... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-16035 json | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send,... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-14300 json | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-14245 json | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass lead... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-12761 json | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentic... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-12695 json | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user... | Not Provided | 2026-07-31 | 2026-07-31 |