Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Saml Sso Service Provider HIGH 7.4
CVE-2026-5343

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue aff…

Fix: 3.1.4+
Fix from $1,950 2026-05-28
Saml Sso Service Provider MEDIUM 6.1
CVE-2026-3217

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross…

Fix: 3.1.3+
Fix from $1,600 2026-03-25
Miniorange 2fa HIGH 8.8
CVE-2025-47708

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterp…

Fix: 5.2.0 / 8.x-4.7+
Fix from $1,950 2025-05-14
Miniorange 2fa HIGH 7.4
CVE-2025-47710

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This is…

Fix: 5.2.0 / 8.x-4.7+
Fix from $1,950 2025-05-14
Miniorange 2fa MEDIUM 6.5
CVE-2025-47709

Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Dr…

Fix: 5.2.0 / 8.x-4.7+
Fix from $1,600 2025-05-14
Miniorange 2fa HIGH 7.5
CVE-2025-47707

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This is…

Fix: 5.2.0 / 8.x-4.7+
Fix from $1,950 2025-05-14
Social Login CRITICAL 9.8
CVE-2024-11087

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass i…

Fix: after 200.3.9
Fix from $2,300 2025-03-08
Oauth \& Openid Connect Single Sign On MEDIUM 6.1
CVE-2024-13301

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – …

Fix: 3.44.0 / 4.0.19+
Fix from $1,600 2025-01-09
Page Restriction HIGH 7.5
CVE-2024-11297

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t…

Fix: 1.3.7+
Fix from $1,950 2024-12-20
Otp Verification With Firebase CRITICAL 9.8
CVE-2024-9862

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, …

Fix: 3.6.1+
Fix from $2,300 2024-10-17
Otp Verification With Firebase HIGH 8.1
CVE-2024-9861

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. Th…

Fix: 3.6.1+
Fix from $1,950 2024-10-17
Web Application Firewall MEDIUM 5.3
CVE-2022-4539

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insuff…

Fix: 2.1.3+
Fix from $1,600 2024-08-31
Page Restriction MEDIUM 5.3
CVE-2024-0681

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and i…

Fix: 1.3.5+
Fix from $1,600 2024-03-13
Malware Scanner HIGH 7.2
CVE-2024-25902

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects M…

Fix: 4.7.3+
Fix from $1,950 2024-02-28
Web3 Crypto Wallet Login \& Nft Token Gating CRITICAL 9.8
CVE-2023-6036

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functi…

Fix: 3.0.0+
Fix from $2,300 2024-02-12
Staff \/ Employee Business Directory For Active Directory MEDIUM 5.4
CVE-2023-4757

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP s…

Fix: 1.2.3+
Fix from $1,600 2024-01-16
Google Authenticator HIGH 7.5
CVE-2022-44589

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authe…

Fix: 5.6.2+
Fix from $1,950 2023-12-29
Google Authenticator MEDIUM 5.3
CVE-2022-4943

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plug…

Fix: after 5.6.5
Fix from $1,600 2023-10-20
Active Directory Integration \/ Ldap Integration HIGH 7.5
CVE-2023-5003EPSS 26%

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator …

Fix: 4.1.10+
Fix from $1,950 2023-10-16
Active Directory Integration \/ Ldap Integration MEDIUM 6.5
CVE-2023-4506

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. Thi…

Fix: after 4.1.10
Fix from $1,600 2023-09-27
Prevent Files \/ Folders Access HIGH 7.2
CVE-2023-4238

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitr…

Fix: 2.5.2+
Fix from $1,950 2023-09-25
Oauth Single Sign On HIGH 8.8
CVE-2022-34155

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects …

Fix: 6.23.4+
Fix from $1,950 2023-07-18
Web3 Crypto Wallet Login \& Nft Token Gating CRITICAL 9.8
CVE-2023-3249

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0…

Fix: after 2.6.0
Fix from $2,300 2023-06-30
Active Directory Integration \/ Ldap Integration HIGH 7.6
CVE-2023-3447

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. Thi…

Fix: 4.1.6+
Fix from $1,950 2023-06-29
Wordpress Social Login And Register \(discord\, Google\, Twitter\, Linkedin\) CRITICAL 9.8
CVE-2023-2982EPSS 46%

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions …

Fix: 7.6.5+
Fix from $2,300 2023-06-29
Active Directory Integration \/ Ldap Integration MEDIUM 6.5
CVE-2023-2599

The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby…

Fix: after 4.1.4
Fix from $1,600 2023-06-09
Wordpress Social Login And Register \(discord\, Google\, Twitter\, Linkedin\) HIGH 8.8
CVE-2023-23706

Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.…

Fix: 7.6.0+
Fix from $1,950 2023-05-23
Active Directory Integration \/ Ldap Integration HIGH 7.5
CVE-2023-0812

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST re…

Fix: 4.1.1+
Fix from $1,950 2023-05-15
Oauth Single Sign On MEDIUM 6.5
CVE-2023-1092

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Prem…

Fix: 6.24.2 / 28.4.9+
Fix from $1,600 2023-03-27
Oauth Single Sign On MEDIUM 6.5
CVE-2023-1093

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attacke…

Fix: 6.24.2+
Fix from $1,600 2023-03-27