Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Saml Sp Single Sign On MEDIUM 6.1
CVE-2022-4496

The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Prem…

Fix: 12.1.0 / 16.0.8+
Fix from $1,600 2023-01-30
Ldap Integration With Active Directory And Openldap HIGH 7.5
CVE-2023-23749

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly san…

Mitigation only
Fix from $1,950 2023-01-17
Wordpress Rest Api Authentication HIGH 8.8
CVE-2022-45073

Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.

Fix: after 2.4.0
Fix from $1,950 2022-11-18
Google Authenticator HIGH 8.8
CVE-2022-42461

Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.

Fix: 5.6.2+
Fix from $1,950 2022-11-18
Discord Integration MEDIUM 6.5
CVE-2022-3082

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logge…

Fix: 2.1.6+
Fix from $1,600 2022-10-17
Oauth 2.0 Client For Sso CRITICAL 9.8
CVE-2022-34858

Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.

Fix: 1.11.4+
Fix from $2,300 2022-08-22
Wp Oauth Server CRITICAL 9.8
CVE-2022-34149

Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.

Fix: after 3.0.4
Fix from $2,300 2022-08-22
Oauth Single Sign On MEDIUM 5.3
CVE-2022-2133

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to l…

Fix: 6.22.6+
Fix from $1,600 2022-07-17
Google Authenticator HIGH 8.1
CVE-2022-0229

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMet…

Fix: 5.5+
Fix from $1,950 2022-03-21
Saml HIGH 7.5
CVE-2021-36786

The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.

Fix: 1.4.3+
Fix from $1,950 2021-08-13
Saml MEDIUM 5.4
CVE-2021-36785

The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.

Fix: 1.4.3+
Fix from $1,600 2021-08-13
Saml Sp Single Sign On MEDIUM 6.1
CVE-2020-6850

Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php.…

Fix: 4.8.84+
Fix from $1,600 2020-02-17
Saml Sp Single Sign On MEDIUM 6.1
CVE-2019-12346

In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAM…

Fix: 4.8.73+
Fix from $1,600 2019-06-24