SecAlerts
m

miniorange

Security Risk Profile

64
/100
high

Security Risk Score

Comprehensive risk assessment based on 83 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 24, 2019 to present

83
Total CVEs
45
Critical+High
0
Exploited
33
Unpatched

Threat Assessment

Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
33
Critical/High
Risk Level
64/100
high
📈 4 in Last 30 Days

Severity Distribution

Critical
18
High
27
Medium
37
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
13

Age Distribution

Common Weaknesses (CWE)

1
XSS
14
2
CSRF
9
3
SQL Injection
4
4
Infoleak
3
5
Path Traversal
1

Most Affected Products

1. miniOrange Saml Sso - Service Provider Drupal78
2. miniOrange Miniorange 2fa Drupal12
3. miniOrange Oauth Single Sign On Wordpress7
4. miniOrange Google Authenticator WordPress6
5. miniOrange Active Directory Integration \/ Ldap Integration Wordpress6

Recent Vulnerabilities

See more →
CVE-2026-97274
CVSS 9.8EPSS 0%critical

WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability

Sep 30, 2026🔧 No Patch
CVE-2026-85984
CVSS 9.8critical

miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter

Sep 26, 2026🔧 No Patch
CVE-2026-89027
CVSS 6.9medium

miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade

Sep 15, 2026🔧 No Patch
CVE-2026-77770
CVSS 10.0critical

miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator

Sep 10, 2026🔧 No Patch
CVE-2026-81205
CVSS 5.3medium

LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115

Sep 2, 2026🔧 No Patch
CVE-2026-77995
CVSS 10.0critical

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2

Aug 24, 2026🔧 No Patch
CVE-2026-61967
CVSS 9.8critical

WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability

Aug 13, 2026🔧 No Patch
CVE-2026-16619
CVSS 7.5high

miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts

Aug 6, 2026🔧 No Patch
CVE-2026-16035
CVSS 4.3medium

miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send

Aug 4, 2026🔧 No Patch
CVE-2026-14300
CVSS 8.1high

miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover

Jul 29, 2026🔧 No Patch

Monitor miniorange in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.