Known Vulnerabilities for Miniorange by Vendor
Listed below are 10 of the newest known vulnerabilities associated with "Miniorange" by "Vendor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89027 json | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade ... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-78074 json | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a... | Not Provided | 2026-08-31 | 2026-09-08 |
| CVE-2026-77998 json | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO <... | Not Provided | 2026-08-25 | 2026-09-08 |
| CVE-2026-77995 json | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – O... | Not Provided | 2026-08-24 | 2026-09-08 |
| CVE-2026-77771 json | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-fac... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-77770 json | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-61967 json | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-61957 json | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59545 json | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-57807 json | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single ... | Not Provided | 2026-07-10 | 2026-07-21 |