« Volver al listado

Miniorange

Miniorange 2FA: vulnerabilidades y CVE

Miniorange 2FA tiene 12 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses6
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77771Alta (7.5)0.32%—10 sept 2026
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client…
CVE-2026-77770Crítica (10)0.44%—10 sept 2026
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input,…
CVE-2026-16619Alta (7.5)0.32%—6 ago 2026
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing…
CVE-2026-16036Alta (7.5)0.43%—5 ago 2026
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a…
CVE-2026-16035Media (4.3)0.33%—4 ago 2026
The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user…
CVE-2026-12695Alta (8.1)0.29%—31 jul 2026
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an…
CVE-2025-6675Media (4.8)0.24%—26 jun 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0,…
CVE-2025-47710Alta (7.4)0.37%—14 may 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0,…
CVE-2025-47709Media (6.5)0.24%—14 may 2025
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
CVE-2025-47708Alta (8.8)0.19%—14 may 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before…
CVE-2025-47707Alta (7.5)0.41%—14 may 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0,…
CVE-2025-47706Media (4.8)0.27%—14 may 2025
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts6
  2. T1190 Exploit Public-Facing Application5
  3. T1210 Exploitation of Remote Services2
  4. T1078.001 Default Accounts1
  5. T1185 Browser Session Hijacking1
  6. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Miniorange