Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2026-5343 Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue aff… Saml Sso Service Provider 3.1.4+ Fix from $1,9502026-05-28 MEDIUM 6.1 CVE-2026-3217 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross… Saml Sso Service Provider 3.1.3+ Fix from $1,6002026-03-25 HIGH 8.8 CVE-2025-47708 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterp… Miniorange 2fa 5.2.0 / 8.x-4.7+ Fix from $1,9502025-05-14 HIGH 7.4 CVE-2025-47710 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This is… Miniorange 2fa 5.2.0 / 8.x-4.7+ Fix from $1,9502025-05-14 MEDIUM 6.5 CVE-2025-47709 Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Dr… Miniorange 2fa 5.2.0 / 8.x-4.7+ Fix from $1,6002025-05-14 HIGH 7.5 CVE-2025-47707 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This is… Miniorange 2fa 5.2.0 / 8.x-4.7+ Fix from $1,9502025-05-14 CRITICAL 9.8 CVE-2024-11087 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass i… Social Login after 200.3.9 Fix from $2,3002025-03-08 MEDIUM 6.1 CVE-2024-13301 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – … Oauth \& Openid Connect Single Sign On 3.44.0 / 4.0.19+ Fix from $1,6002025-01-09 HIGH 7.5 CVE-2024-11297 The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… Page Restriction 1.3.7+ Fix from $1,9502024-12-20 CRITICAL 9.8 CVE-2024-9862 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, … Otp Verification With Firebase 3.6.1+ Fix from $2,3002024-10-17 HIGH 8.1 CVE-2024-9861 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. Th… Otp Verification With Firebase 3.6.1+ Fix from $1,9502024-10-17 MEDIUM 5.3 CVE-2022-4539 The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insuff… Web Application Firewall 2.1.3+ Fix from $1,6002024-08-31 MEDIUM 5.3 CVE-2024-0681 The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and i… Page Restriction 1.3.5+ Fix from $1,6002024-03-13 HIGH 7.2 CVE-2024-25902 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects M… Malware Scanner 4.7.3+ Fix from $1,9502024-02-28 CRITICAL 9.8 CVE-2023-6036 The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functi… Web3 Crypto Wallet Login \& Nft Token Gating 3.0.0+ Fix from $2,3002024-02-12 MEDIUM 5.4 CVE-2023-4757 The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP s… Staff \/ Employee Business Directory For Active Directory 1.2.3+ Fix from $1,6002024-01-16 HIGH 7.5 CVE-2022-44589 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authe… Google Authenticator 5.6.2+ Fix from $1,9502023-12-29 MEDIUM 5.3 CVE-2022-4943 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plug… Google Authenticator after 5.6.5 Fix from $1,6002023-10-20 HIGH 7.5 CVE-2023-5003EPSS 26% The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator … Active Directory Integration \/ Ldap Integration 4.1.10+ Fix from $1,9502023-10-16 MEDIUM 6.5 CVE-2023-4506 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. Thi… Active Directory Integration \/ Ldap Integration after 4.1.10 Fix from $1,6002023-09-27 HIGH 7.2 CVE-2023-4238 The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitr… Prevent Files \/ Folders Access 2.5.2+ Fix from $1,9502023-09-25 HIGH 8.8 CVE-2022-34155 Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects … Oauth Single Sign On 6.23.4+ Fix from $1,9502023-07-18 CRITICAL 9.8 CVE-2023-3249 The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0… Web3 Crypto Wallet Login \& Nft Token Gating after 2.6.0 Fix from $2,3002023-06-30 HIGH 7.6 CVE-2023-3447 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. Thi… Active Directory Integration \/ Ldap Integration 4.1.6+ Fix from $1,9502023-06-29 CRITICAL 9.8 CVE-2023-2982EPSS 46% The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions … Wordpress Social Login And Register \(discord\, Google\, Twitter\, Linkedin\) 7.6.5+ Fix from $2,3002023-06-29 MEDIUM 6.5 CVE-2023-2599 The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby… Active Directory Integration \/ Ldap Integration after 4.1.4 Fix from $1,6002023-06-09 HIGH 8.8 CVE-2023-23706 Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.… Wordpress Social Login And Register \(discord\, Google\, Twitter\, Linkedin\) 7.6.0+ Fix from $1,9502023-05-23 HIGH 7.5 CVE-2023-0812 The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST re… Active Directory Integration \/ Ldap Integration 4.1.1+ Fix from $1,9502023-05-15 MEDIUM 6.5 CVE-2023-1092 The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Prem… Oauth Single Sign On 6.24.2 / 28.4.9+ Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-1093 The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attacke… Oauth Single Sign On 6.24.2+ Fix from $1,6002023-03-27