Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.18% | — | Miniorange Google AuthenticatorAI | 6/8/2026 | 26/8/2026 | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account. | |
| Modificada | Alta (7.5) | 0.70% | — | Miniorange Google Authenticator | 29/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA ,… | |
| Modificada | Media (5.3) | 0.54% | — | Miniorange Google Authenticator | 20/10/2023 | 17/6/2026 | The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings. | |
| Modificada | Alta (8.8) | 0.69% | — | Miniorange Google Authenticator | 18/11/2022 | 17/6/2026 | Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress. | |
| Modificada | Media (4.8) | 0.59% | — | Miniorange Login With OTP Over Sms, Email, Whatsapp AND Google Authenticator | 27/6/2022 | 17/6/2026 | The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Media (4.8) | 0.59% | — | Miniorange Google Authenticator | 27/6/2022 | 17/6/2026 | The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup) | |
| Modificada | Media (4.3) | 0.43% | — | Miniorange Google Authenticator | 27/6/2022 | 17/6/2026 | The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks | |
| Modificada | Alta (8.1) | 0.55% | — | Miniorange Google Authenticator | 21/3/2022 | 17/6/2026 | The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable. | |
| Modificada | Media (5) | 1.3% | — | Google Authenticator Login Project GA Login | 29/5/2014 | 16/6/2026 | The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP). | |
| Modificada | Media (5) | 1.4% | — | Google Authenticator Login Project GA Login | 29/5/2014 | 16/6/2026 | The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors. | |
| Modificada | Media (6.8) | 1.4% | — | Google Authenticator Login Project GA Login | 27/3/2013 | 16/6/2026 | The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username. |