{"schema_version":1,"title":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange Saml vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange Saml: 0 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-87953, was published on 9 September 2026.","url":"https://junglewise.ai/threats/technologies/drupal-miniorange-saml","json_url":"https://junglewise.ai/threats/technologies/drupal-miniorange-saml.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/drupal-miniorange-saml","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":11,"last_90_days":11,"last_365_days":13},"latest":[{"cve":"CVE-2026-87953","slug":"cve-2026-87953-drupal-contrib-2026-151-this-module-allows-you-to-configure-your","title":"miniorange_saml SAML Service Provider URL validation bypass","severity":"info","exploited":false,"published_at":"2026-09-09T17:23:34+00:00","url":"https://junglewise.ai/threats/cve-2026-87953-drupal-contrib-2026-151-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87952","slug":"cve-2026-87952-drupal-contrib-2026-150-this-module-allows-you-to-configure-your","title":"Drupal miniorange_saml SAML assertion replay in authentication","severity":"info","exploited":false,"published_at":"2026-09-09T17:23:14+00:00","url":"https://junglewise.ai/threats/cve-2026-87952-drupal-contrib-2026-150-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87951","slug":"cve-2026-87951-drupal-contrib-2026-149-this-module-allows-you-to-configure-your","title":"Drupal SAML SSO Service Provider information disclosure in configuration storage","severity":"info","exploited":false,"published_at":"2026-09-09T17:22:55+00:00","url":"https://junglewise.ai/threats/cve-2026-87951-drupal-contrib-2026-149-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87950","slug":"cve-2026-87950-drupal-contrib-2026-148-this-module-allows-you-to-configure-your","title":"miniOrange SAML Service Provider embedded credentials information disclosure","severity":"info","exploited":false,"published_at":"2026-09-09T17:22:34+00:00","url":"https://junglewise.ai/threats/cve-2026-87950-drupal-contrib-2026-148-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87949","slug":"cve-2026-87949-drupal-contrib-2026-147-this-module-allows-you-to-configure-your","title":"SAML SSO Service Provider cross-site scripting in SAML assertion display","severity":"info","exploited":false,"published_at":"2026-09-09T17:22:13+00:00","url":"https://junglewise.ai/threats/cve-2026-87949-drupal-contrib-2026-147-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87948","slug":"cve-2026-87948-drupal-contrib-2026-146-this-module-allows-you-to-configure-your","title":"Drupal SAML SSO Service Provider cross-site scripting in HTML output","severity":"info","exploited":false,"published_at":"2026-09-09T17:21:49+00:00","url":"https://junglewise.ai/threats/cve-2026-87948-drupal-contrib-2026-146-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87947","slug":"cve-2026-87947-drupal-contrib-2026-145-this-module-allows-you-to-configure-your","title":"Drupal miniorange_saml signature algorithm verification bypass","severity":"info","exploited":false,"published_at":"2026-09-09T17:21:27+00:00","url":"https://junglewise.ai/threats/cve-2026-87947-drupal-contrib-2026-145-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87946","slug":"cve-2026-87946-drupal-contrib-2026-144-this-module-allows-you-to-configure-your","title":"Drupal SAML SSO Service Provider weak cryptographic practices","severity":"info","exploited":false,"published_at":"2026-09-09T17:21:01+00:00","url":"https://junglewise.ai/threats/cve-2026-87946-drupal-contrib-2026-144-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87945","slug":"cve-2026-87945-drupal-contrib-2026-143-this-module-allows-you-to-configure-your","title":"Drupal miniorange_saml open redirect in URL validation","severity":"info","exploited":false,"published_at":"2026-09-09T17:20:35+00:00","url":"https://junglewise.ai/threats/cve-2026-87945-drupal-contrib-2026-143-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87944","slug":"cve-2026-87944-drupal-contrib-2026-142-this-module-allows-you-to-configure-your","title":"Drupal SAML SSO Service Provider TLS certificate validation bypass","severity":"info","exploited":false,"published_at":"2026-09-09T17:20:12+00:00","url":"https://junglewise.ai/threats/cve-2026-87944-drupal-contrib-2026-142-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87943","slug":"cve-2026-87943-drupal-contrib-2026-141-this-module-allows-you-to-configure-your","title":"Drupal miniorange_saml improper access control","severity":"info","exploited":false,"published_at":"2026-09-09T17:19:43+00:00","url":"https://junglewise.ai/threats/cve-2026-87943-drupal-contrib-2026-141-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-5343","cvss":9.8,"epss":0.0034,"slug":"cve-2026-5343-drupal-saml-sso-service-provider-authentication-bypass","title":"Drupal SAML SSO - Service Provider authentication bypass","severity":"info","exploited":false,"published_at":"2026-05-28T23:16:44.52+00:00","url":"https://junglewise.ai/threats/cve-2026-5343-drupal-saml-sso-service-provider-authentication-bypass"},{"cve":"CVE-2026-3217","epss":0.0025,"slug":"cve-2026-3217-drupal-contrib-2026-018-this-module-enables-you-to-perform-saml","title":"DRUPAL-CONTRIB-2026-018 - This module enables you to perform SAML protocol-based single sign-on (SSO) on a Drupal site. The module doesn't sufficiently sanitize user","severity":"info","exploited":false,"published_at":"2026-02-25T18:51:26+00:00","url":"https://junglewise.ai/threats/cve-2026-3217-drupal-contrib-2026-018-this-module-enables-you-to-perform-saml"},{"slug":"drupal-contrib-2021-036-this-module-provides-a-solution-to-authenticate-66c8cb64","title":"DRUPAL-CONTRIB-2021-036 - This module provides a solution to authenticate visitors using existing SAML providers. Certain non-default configurations allow a maliciou","severity":"info","exploited":false,"published_at":"2021-09-22T17:12:02+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2021-036-this-module-provides-a-solution-to-authenticate-66c8cb64"},{"slug":"drupal-contrib-2020-038-this-module-enables-your-users-residing-at-a-344127de","title":"DRUPAL-CONTRIB-2020-038 - This module enables your users residing at a SAML 2.0 compliant Identity Provider to login to your Drupal website. The module has two Authe","severity":"info","exploited":false,"published_at":"2020-11-18T17:27:58+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2020-038-this-module-enables-your-users-residing-at-a-344127de"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Webform","slug":"drupal-webform","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/drupal-webform"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Social","slug":"drupal-social","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/drupal-social"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Ai","slug":"drupal-ai","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/drupal-ai"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Jsonapi","slug":"drupal-jsonapi","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-jsonapi"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange 2fa","slug":"drupal-miniorange-2fa","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-2fa"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Facets","slug":"drupal-facets","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-facets"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Permissions By Term","slug":"drupal-permissions-by-term","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-permissions-by-term"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Tfa","slug":"drupal-tfa","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-tfa"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Apigee Edge","slug":"drupal-apigee-edge","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-apigee-edge"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cleantalk","slug":"drupal-cleantalk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cleantalk"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Commerce","slug":"drupal-commerce","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-commerce"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cookies","slug":"drupal-cookies","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cookies"}],"technology":{"hub":true,"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange Saml","slug":"drupal-miniorange-saml","vendor":{"name":"Packagist:Https://Packages.drupal.org/8","slug":"packagist-https-packages-drupal-org-8","url":"https://junglewise.ai/threats/vendors/packagist-https-packages-drupal-org-8"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-saml"},"most_severe":[{"cve":"CVE-2026-5343","cvss":9.8,"epss":0.0034,"slug":"cve-2026-5343-drupal-saml-sso-service-provider-authentication-bypass","title":"Drupal SAML SSO - Service Provider authentication bypass","severity":"info","exploited":false,"published_at":"2026-05-28T23:16:44.52+00:00","url":"https://junglewise.ai/threats/cve-2026-5343-drupal-saml-sso-service-provider-authentication-bypass"},{"cve":"CVE-2026-3217","epss":0.0025,"slug":"cve-2026-3217-drupal-contrib-2026-018-this-module-enables-you-to-perform-saml","title":"DRUPAL-CONTRIB-2026-018 - This module enables you to perform SAML protocol-based single sign-on (SSO) on a Drupal site. The module doesn't sufficiently sanitize user","severity":"info","exploited":false,"published_at":"2026-02-25T18:51:26+00:00","url":"https://junglewise.ai/threats/cve-2026-3217-drupal-contrib-2026-018-this-module-enables-you-to-perform-saml"},{"cve":"CVE-2026-87953","slug":"cve-2026-87953-drupal-contrib-2026-151-this-module-allows-you-to-configure-your","title":"miniorange_saml SAML Service Provider URL validation bypass","severity":"info","exploited":false,"published_at":"2026-09-09T17:23:34+00:00","url":"https://junglewise.ai/threats/cve-2026-87953-drupal-contrib-2026-151-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87952","slug":"cve-2026-87952-drupal-contrib-2026-150-this-module-allows-you-to-configure-your","title":"Drupal miniorange_saml SAML assertion replay in authentication","severity":"info","exploited":false,"published_at":"2026-09-09T17:23:14+00:00","url":"https://junglewise.ai/threats/cve-2026-87952-drupal-contrib-2026-150-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87951","slug":"cve-2026-87951-drupal-contrib-2026-149-this-module-allows-you-to-configure-your","title":"Drupal SAML SSO Service Provider information disclosure in configuration storage","severity":"info","exploited":false,"published_at":"2026-09-09T17:22:55+00:00","url":"https://junglewise.ai/threats/cve-2026-87951-drupal-contrib-2026-149-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87950","slug":"cve-2026-87950-drupal-contrib-2026-148-this-module-allows-you-to-configure-your","title":"miniOrange SAML Service Provider embedded credentials information disclosure","severity":"info","exploited":false,"published_at":"2026-09-09T17:22:34+00:00","url":"https://junglewise.ai/threats/cve-2026-87950-drupal-contrib-2026-148-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87949","slug":"cve-2026-87949-drupal-contrib-2026-147-this-module-allows-you-to-configure-your","title":"SAML SSO Service Provider cross-site scripting in SAML assertion display","severity":"info","exploited":false,"published_at":"2026-09-09T17:22:13+00:00","url":"https://junglewise.ai/threats/cve-2026-87949-drupal-contrib-2026-147-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87948","slug":"cve-2026-87948-drupal-contrib-2026-146-this-module-allows-you-to-configure-your","title":"Drupal SAML SSO Service Provider cross-site scripting in HTML output","severity":"info","exploited":false,"published_at":"2026-09-09T17:21:49+00:00","url":"https://junglewise.ai/threats/cve-2026-87948-drupal-contrib-2026-146-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87947","slug":"cve-2026-87947-drupal-contrib-2026-145-this-module-allows-you-to-configure-your","title":"Drupal miniorange_saml signature algorithm verification bypass","severity":"info","exploited":false,"published_at":"2026-09-09T17:21:27+00:00","url":"https://junglewise.ai/threats/cve-2026-87947-drupal-contrib-2026-145-this-module-allows-you-to-configure-your"},{"cve":"CVE-2026-87946","slug":"cve-2026-87946-drupal-contrib-2026-144-this-module-allows-you-to-configure-your","title":"Drupal SAML SSO Service Provider weak cryptographic practices","severity":"info","exploited":false,"published_at":"2026-09-09T17:21:01+00:00","url":"https://junglewise.ai/threats/cve-2026-87946-drupal-contrib-2026-144-this-module-allows-you-to-configure-your"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}