Vulnerabilities > Miniorange

DATE CVE VULNERABILITY TITLE RISK
2022-06-27 CVE-2022-1028 Cross-site Scripting vulnerability in Miniorange Wordpress Security
The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
network
miniorange CWE-79
3.5
2022-06-27 CVE-2022-1029 Cross-site Scripting vulnerability in Miniorange Limit Login Attempts
The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
network
miniorange CWE-79
3.5
2022-06-27 CVE-2022-1321 Cross-site Scripting vulnerability in Miniorange Google Authenticator
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
network
miniorange CWE-79
3.5
2022-06-27 CVE-2022-1994 Cross-site Scripting vulnerability in Miniorange Login With OTP Over Sms, Email, Whatsapp and Google Authenticator
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
network
miniorange CWE-79
3.5
2022-06-27 CVE-2022-1995 Cross-site Scripting vulnerability in Miniorange Malware Scanner
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
network
miniorange CWE-79
3.5
2022-03-21 CVE-2022-0229 Missing Authorization vulnerability in Miniorange Google Authenticator
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly.
network
low complexity
miniorange CWE-862
8.1
2021-08-13 CVE-2021-36786 Insecure Storage of Sensitive Information vulnerability in Miniorange Saml
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.
network
low complexity
miniorange CWE-922
5.0
2020-02-17 CVE-2020-6850 Cross-site Scripting vulnerability in Miniorange Saml SP Single Sign ON
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php.
network
miniorange CWE-79
4.3
2019-06-24 CVE-2019-12346 Cross-site Scripting vulnerability in Miniorange Saml SP Single Sign ON
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.
network
miniorange CWE-79
4.3