Known Vulnerabilities for Miniorange by Vendor
Listed below are 10 of the newest known vulnerabilities associated with "Miniorange" by "Vendor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77998 json | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO <... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-77995 json | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a coo... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-61967 json | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-61957 json | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59545 json | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-57807 json | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single ... | Not Provided | 2026-07-10 | 2026-07-21 |
| CVE-2026-16619 json | The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, ... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-16036 json | The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-f... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-16035 json | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send,... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-14300 json | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the... | Not Provided | 2026-07-29 | 2026-07-30 |