Google Authenticator
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Google Authenticator. Use it to gauge the current risk picture and drill into individual advisories.
Google Authenticator CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High3
- Medium3
Latest CVEs
The 6 most recently published vulnerabilities affecting Google Authenticator.
- CVE-2022-44589WordPress miniOrange's Google Authenticator Plugin <= 5.6.1 is vulnerable to Sensitive Data Exposure8.1
- CVE-2022-4943miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change7.5
- CVE-2022-42461WordPress miniOrange's Google Authenticator plugin <= 5.6.1 - Broken Access Control vulnerability5.4
- CVE-2022-1321miniOrange's Google Authenticator < 5.5.6 - Admin+ Stored Cross-Site Scripting4.8
- CVE-2022-0875miniOrange Google Authenticator < 1.0.5 - CSRF to Stored Cross-Site Scripting4.3
- CVE-2022-0229miniOrange's Google Authenticator < 5.5 - Unauthenticated Arbitrary Options Deletion8.1
Product grouping is registry-driven, with AI assist and human review. How it works