Miniorange
Miniorange 2FA: vulnerabilidades y CVE
Miniorange 2FA tiene 12 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77771 | Alta (7.5) | 0.32% | — | 10 sept 2026 | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client… |
| CVE-2026-77770 | Crítica (10) | 0.44% | — | 10 sept 2026 | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input,… |
| CVE-2026-16619 | Alta (7.5) | 0.32% | — | 6 ago 2026 | The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing… |
| CVE-2026-16036 | Alta (7.5) | 0.43% | — | 5 ago 2026 | The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a… |
| CVE-2026-16035 | Media (4.3) | 0.33% | — | 4 ago 2026 | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user… |
| CVE-2026-12695 | Alta (8.1) | 0.29% | — | 31 jul 2026 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an… |
| CVE-2025-6675 | Media (4.8) | 0.24% | — | 26 jun 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0,… |
| CVE-2025-47710 | Alta (7.4) | 0.37% | — | 14 may 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0,… |
| CVE-2025-47709 | Media (6.5) | 0.24% | — | 14 may 2025 | Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0. |
| CVE-2025-47708 | Alta (8.8) | 0.19% | — | 14 may 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before… |
| CVE-2025-47707 | Alta (7.5) | 0.41% | — | 14 may 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0,… |
| CVE-2025-47706 | Media (4.8) | 0.27% | — | 14 may 2025 | Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Miniorange
Oauth Single Sign ON · 7Google Authenticator · 7Active Directory Integration / Ldap Integration · 6Saml SP Single Sign ON · 5Malware Scanner · 5OTP Verification With Firebase · 4Wordpress Social Login AND Register · 4Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) · 3Discord Integration · 3Page Restriction · 2Custom API FOR WP · 2Password Policy Manager · 2