CVE Tools

Miniorange

40 CVEs tracked since 2022. Since Jun 2022, none of them reached CISA KEV.

Miniorange CVEs per month

Jun 2022 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Miniorange CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0670
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-0130
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-0650
2023-07null or fewer
2023-08null or fewer
2023-0940
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-1260
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-0570
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-0880

Products

The products that kept showing up in Miniorange's monthly top three, with their CVEs summed over those months.

  1. Miniorange 2fa51 month
  2. Active Directory Integration \/ Ldap Integration42 months
  3. WordPress Social Login and Register32 months
  4. Google Authenticator21 month
  5. Headless Single Sign On21 month
  6. Saml Sp Single Sign On22 months
  7. WordPress Social Login and Register (Discord, Google, Twitter, Linkedin)21 month
  8. Limit Login Attempts11 month
  9. Login Using WordPress Users11 month
  10. Miniorange Discord Integration11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Miniorange.

  1. CVE-2026-62108WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability9.8
  2. CVE-2026-89027miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade6.5
  3. CVE-2026-81205LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-1155.3
  4. CVE-2026-82229WordPress WordPress Social Login and Register plugin <= 7.8.2 - Cross Site Scripting (XSS) vulnerability7.1
  5. CVE-2026-73351WordPress WordPress Social Login and Register plugin <= 7.8.1 - Cross Site Scripting (XSS) vulnerability7.1
  6. CVE-2026-61979WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability8.1
  7. CVE-2026-61967WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability9.8
  8. CVE-2026-28149WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability9.8
  9. CVE-2026-28148WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability9.8
  10. CVE-2026-28008WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability9.8
  11. CVE-2026-65520WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability9.3
  12. CVE-2026-61957WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting (XSS) vulnerability7.1
  13. CVE-2026-65561WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability6.5
  14. CVE-2026-59545WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability8.1
  15. CVE-2026-5343SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2026-0317.4

The record

Peak rank
#102 in Jun 2022
Busiest month shown
Aug 2026, 8 CVEs
Months with a KEV entry
0 since Jun 2022
Monthly snapshots
7 since 2022
Miniorange's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store