Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Miniorange

First CVE: Jun 24, 2019Active for: 7 yearsTotal CVEs: 62
33.0
VTI Score
Medium

Miniorange develops a focused suite of authentication and identity-management plugins, primarily for Active Directory and LDAP integration alongside multi-factor authentication and single-sign-on capabilities, that secure access to widely deployed business applications. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability that reflects the high-value nature of authentication-layer flaws. The exposure recurs across its identity-platform product line through weakness classes including cross-site scripting, cross-site request forgery, authentication bypass, and missing authentication for critical functions—gaps that are characteristic of complex identity-federation and session-management implementations. Because these products sit in the authentication path of many enterprise systems, flaws in this vendor's offerings can provide broad lateral access; defenders should prioritize this vendor's updates for identity and access-control components. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
62
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Miniorange over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2019
7 years ago
Most Recent CVE
May 28, 2026
58 days ago

Products(27 total)

Top CVEs

Signals from CVEs in this vendor scope (62 CVEs).

62 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2982CRITICAL
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. Th
Jun 29, 20239.867NOYES
CVE-2023-5003HIGH
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfo
Oct 16, 20237.546NOYES
CVE-2026-5343HIGH
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provide
May 28, 20267.431NONO
CVE-2022-34858CRITICAL
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Aug 22, 20229.831NONO
CVE-2024-11087CRITICAL
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inclu
Mar 8, 20259.830NONO
CVE-2022-34149CRITICAL
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
Aug 22, 20229.830NONO
CVE-2023-6036CRITICAL
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and '
Feb 12, 20249.829NONO
CVE-2023-3249CRITICAL
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect auth
Jun 30, 20239.829NONO
CVE-2024-9862CRITICAL
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugi
Oct 17, 20249.828NONO
CVE-2022-45073HIGH
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
Nov 18, 20228.827NONO
View all 62 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products62 CVEs
55%
32%
11%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network62 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (91.9%)
High5 (8.1%)
Unknown0 (0.0%)
User Interaction
None37 (59.7%)
Unknown0 (0.0%)
Required25 (40.3%)
Privileges Required
Low10 (16.1%)
High13 (21.0%)
None39 (62.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (62 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Miniorange.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Miniorange — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Miniorange's Products

View all 6 CNAs →

Top CWEs