{"schema_version":1,"title":"miniOrange vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 27 vulnerabilities in miniOrange: 2 in the last 7 days and 24 in the last 90 days, 10 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82843, was published on 23 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/miniorange","json_url":"https://junglewise.ai/threats/vendors/miniorange.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/miniorange","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":9,"all_time":27,"critical":10,"exploited":0,"last_7_days":2,"last_30_days":10,"last_90_days":24,"last_365_days":27},"latest":[{"cve":"CVE-2026-82843","cvss":9,"epss":0.0019,"slug":"cve-2026-82843-the-wp-oauth-server-login-with-wordpress-wordpress-plugin-before","title":"WP OAuth Server OpenID Connect identity assertion binding bypass","severity":"critical","exploited":false,"published_at":"2026-09-23T06:17:02.363+00:00","url":"https://junglewise.ai/threats/cve-2026-82843-the-wp-oauth-server-login-with-wordpress-wordpress-plugin-before"},{"cve":"CVE-2026-82842","cvss":8.1,"epss":0.0037,"slug":"cve-2026-82842-the-saml-single-sign-on-wordpress-plugin-before-6-0-0-does-not","title":"miniorange SAML Single Sign On privilege escalation via account matching","severity":"high","exploited":false,"published_at":"2026-09-20T07:16:50.093+00:00","url":"https://junglewise.ai/threats/cve-2026-82842-the-saml-single-sign-on-wordpress-plugin-before-6-0-0-does-not"},{"cve":"CVE-2026-62108","cvss":9.8,"epss":0.0061,"slug":"cve-2026-62108-headless-single-sign-on-broken-authentication-bypass","title":"Headless Single Sign On broken authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-17T14:17:15.263+00:00","url":"https://junglewise.ai/threats/cve-2026-62108-headless-single-sign-on-broken-authentication-bypass"},{"cve":"CVE-2026-89027","cvss":6.5,"epss":0.0038,"slug":"cve-2026-89027-miniorange-jwt-authentication-for-wp-rest-apis-authentication","title":"miniOrange JWT Authentication for WP REST APIs authentication method downgrade","severity":"medium","exploited":false,"published_at":"2026-09-15T20:19:20.093+00:00","url":"https://junglewise.ai/threats/cve-2026-89027-miniorange-jwt-authentication-for-wp-rest-apis-authentication"},{"cve":"CVE-2026-77771","cvss":7.5,"epss":0.0032,"slug":"cve-2026-77771-miniorange-2fa-2fa-bypass-via-unscoped-attempt-limit","title":"miniOrange 2FA 2FA bypass via unscoped attempt limit","severity":"high","exploited":false,"published_at":"2026-09-10T07:17:03.047+00:00","url":"https://junglewise.ai/threats/cve-2026-77771-miniorange-2fa-2fa-bypass-via-unscoped-attempt-limit"},{"cve":"CVE-2026-77770","cvss":10,"epss":0.0044,"slug":"cve-2026-77770-miniorange-2fa-missing-authorization-in-option-deletion","title":"miniOrange 2FA missing authorization in option deletion","severity":"critical","exploited":false,"published_at":"2026-09-10T07:17:02.943+00:00","url":"https://junglewise.ai/threats/cve-2026-77770-miniorange-2fa-missing-authorization-in-option-deletion"},{"cve":"CVE-2026-82183","cvss":8.1,"epss":0.0038,"slug":"cve-2026-82183-miniorange-oauth-single-sign-on-authentication-bypass-in-steam","title":"miniOrange OAuth Single Sign On authentication bypass in Steam OpenID","severity":"high","exploited":false,"published_at":"2026-09-02T06:17:19.987+00:00","url":"https://junglewise.ai/threats/cve-2026-82183-miniorange-oauth-single-sign-on-authentication-bypass-in-steam"},{"cve":"CVE-2026-82229","cvss":7.1,"epss":0.0025,"slug":"cve-2026-82229-wordpress-social-login-and-register-xss","title":"WordPress Social Login and Register XSS","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:53.717+00:00","url":"https://junglewise.ai/threats/cve-2026-82229-wordpress-social-login-and-register-xss"},{"cve":"CVE-2026-78074","epss":0.0054,"slug":"cve-2026-78074-miniorange-joomla-extensions-unauthenticated-arbitrary-extension","title":"miniOrange Joomla Extensions unauthenticated arbitrary extension deinstallation","severity":"info","exploited":false,"published_at":"2026-08-31T14:17:23.633+00:00","url":"https://junglewise.ai/threats/cve-2026-78074-miniorange-joomla-extensions-unauthenticated-arbitrary-extension"},{"cve":"CVE-2026-75807","cvss":7.5,"epss":0.0041,"slug":"cve-2026-75807-miniorange-saml-single-sign-on-authentication-bypass","title":"miniOrange SAML Single Sign On authentication bypass","severity":"high","exploited":false,"published_at":"2026-08-29T18:16:36.313+00:00","url":"https://junglewise.ai/threats/cve-2026-75807-miniorange-saml-single-sign-on-authentication-bypass"},{"cve":"CVE-2026-19715","cvss":7.5,"epss":0.0026,"slug":"cve-2026-19715-wp-oauth-server-debug-log-information-disclosure","title":"WP OAuth Server debug log information disclosure","severity":"high","exploited":false,"published_at":"2026-08-27T06:16:57.44+00:00","url":"https://junglewise.ai/threats/cve-2026-19715-wp-oauth-server-debug-log-information-disclosure"},{"cve":"CVE-2026-77998","epss":0.006,"slug":"cve-2026-77998-miniorange-saml-sso-authentication-bypass-via-samlresponse","title":"miniOrange SAML SSO authentication bypass via SAMLResponse","severity":"info","exploited":false,"published_at":"2026-08-25T13:19:30.817+00:00","url":"https://junglewise.ai/threats/cve-2026-77998-miniorange-saml-sso-authentication-bypass-via-samlresponse"},{"cve":"CVE-2026-77995","epss":0.0041,"slug":"cve-2026-77995-miniorange-oauth-client-arbitrary-account-takeover-via-cookie","title":"miniOrange OAuth Client arbitrary account takeover via cookie manipulation","severity":"info","exploited":false,"published_at":"2026-08-24T14:17:03.403+00:00","url":"https://junglewise.ai/threats/cve-2026-77995-miniorange-oauth-client-arbitrary-account-takeover-via-cookie"},{"cve":"CVE-2026-16035","cvss":4.3,"epss":0.0033,"slug":"cve-2026-16035-miniorange-2fa-arbitrary-recipient-otp-send-in-wordpress-plugin","title":"miniOrange 2FA arbitrary-recipient OTP send in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-08-04T07:16:29.37+00:00","url":"https://junglewise.ai/threats/cve-2026-16035-miniorange-2fa-arbitrary-recipient-otp-send-in-wordpress-plugin"},{"cve":"CVE-2026-12695","cvss":8.1,"slug":"cve-2026-12695-miniorange-2fa-wordpress-plugin-authentication-bypass-via-ga","title":"miniOrange 2FA WordPress plugin authentication bypass via ga_secret","severity":"info","exploited":false,"published_at":"2026-07-31T07:16:23.747+00:00","url":"https://junglewise.ai/threats/cve-2026-12695-miniorange-2fa-wordpress-plugin-authentication-bypass-via-ga"},{"cve":"CVE-2026-14300","cvss":8.1,"slug":"cve-2026-14300-miniorange-social-login-and-register-account-takeover-in-profile","title":"miniOrange Social Login and Register account takeover in Profile Completion","severity":"info","exploited":false,"published_at":"2026-07-29T07:16:41.857+00:00","url":"https://junglewise.ai/threats/cve-2026-14300-miniorange-social-login-and-register-account-takeover-in-profile"},{"cve":"CVE-2026-61957","cvss":7.1,"slug":"cve-2026-61957-miniorange-otp-verification-unauthenticated-xss","title":"miniOrange OTP Verification unauthenticated XSS","severity":"high","exploited":false,"published_at":"2026-07-27T23:16:41.41+00:00","url":"https://junglewise.ai/threats/cve-2026-61957-miniorange-otp-verification-unauthenticated-xss"},{"cve":"CVE-2026-65561","cvss":6.5,"slug":"cve-2026-65561-miniorange-wordpress-social-login-and-register-xss-in-contributor","title":"miniOrange WordPress Social Login and Register XSS in Contributor role","severity":"medium","exploited":false,"published_at":"2026-07-27T15:17:09.357+00:00","url":"https://junglewise.ai/threats/cve-2026-65561-miniorange-wordpress-social-login-and-register-xss-in-contributor"},{"cve":"CVE-2026-15981","cvss":9.8,"slug":"cve-2026-15981-miniorange-saml-single-sign-on-authentication-bypass-in-sso-login","title":"miniOrange SAML Single Sign On authentication bypass in SSO Login plugin","severity":"critical","exploited":false,"published_at":"2026-07-23T21:17:03.22+00:00","url":"https://junglewise.ai/threats/cve-2026-15981-miniorange-saml-single-sign-on-authentication-bypass-in-sso-login"},{"cve":"CVE-2026-59545","cvss":8.1,"slug":"cve-2026-59545-miniorange-discord-integration-authentication-bypass-in-oauth","title":"miniOrange Discord Integration authentication bypass in OAuth callback","severity":"high","exploited":false,"published_at":"2026-07-23T12:18:33.433+00:00","url":"https://junglewise.ai/threats/cve-2026-59545-miniorange-discord-integration-authentication-bypass-in-oauth"},{"cve":"CVE-2026-15013","cvss":9.8,"slug":"cve-2026-15013-miniorange-saml-single-sign-on-authentication-bypass-via","title":"miniOrange SAML Single Sign On authentication bypass via algorithm confusion","severity":"critical","exploited":false,"published_at":"2026-07-16T05:16:18.043+00:00","url":"https://junglewise.ai/threats/cve-2026-15013-miniorange-saml-single-sign-on-authentication-bypass-via"},{"cve":"CVE-2026-57807","cvss":9.8,"slug":"cve-2026-57807-miniorange-oauth-single-sign-on-authentication-bypass-in-oauth","title":"miniOrange OAuth Single Sign On authentication bypass in OAuth Client","severity":"critical","exploited":false,"published_at":"2026-07-10T21:16:59.947+00:00","url":"https://junglewise.ai/threats/cve-2026-57807-miniorange-oauth-single-sign-on-authentication-bypass-in-oauth"},{"cve":"CVE-2026-12761","cvss":9.8,"slug":"cve-2026-12761-miniorange-social-login-and-register-authentication-bypass-in","title":"miniOrange Social Login and Register authentication bypass in Profile Completion flow","severity":"critical","exploited":false,"published_at":"2026-07-10T21:16:53.16+00:00","url":"https://junglewise.ai/threats/cve-2026-12761-miniorange-social-login-and-register-authentication-bypass-in"},{"cve":"CVE-2026-14245","cvss":9.8,"slug":"cve-2026-14245-miniorange-otp-login-authentication-bypass-in-ultimate-member","title":"miniOrange OTP Login authentication bypass in Ultimate Member reset hook","severity":"critical","exploited":false,"published_at":"2026-07-09T08:16:46.933+00:00","url":"https://junglewise.ai/threats/cve-2026-14245-miniorange-otp-login-authentication-bypass-in-ultimate-member"},{"cve":"CVE-2026-42731","cvss":9.8,"slug":"cve-2026-42731-miniorange-otp-verification-privilege-escalation","title":"miniOrange OTP Verification privilege escalation","severity":"critical","exploited":false,"published_at":"2026-05-27T11:16:19.6+00:00","url":"https://junglewise.ai/threats/cve-2026-42731-miniorange-otp-verification-privilege-escalation"}],"vendor":{"hub":true,"name":"miniOrange","slug":"miniorange","homepage":"https://www.miniorange.com/","description":"miniOrange is a provider of identity and access management solutions, including single sign-on and multi-factor authentication.","url":"https://junglewise.ai/threats/vendors/miniorange"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":3,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-77770","cvss":10,"epss":0.0044,"slug":"cve-2026-77770-miniorange-2fa-missing-authorization-in-option-deletion","title":"miniOrange 2FA missing authorization in option deletion","severity":"critical","exploited":false,"published_at":"2026-09-10T07:17:02.943+00:00","url":"https://junglewise.ai/threats/cve-2026-77770-miniorange-2fa-missing-authorization-in-option-deletion"},{"cve":"CVE-2026-62108","cvss":9.8,"epss":0.0061,"slug":"cve-2026-62108-headless-single-sign-on-broken-authentication-bypass","title":"Headless Single Sign On broken authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-17T14:17:15.263+00:00","url":"https://junglewise.ai/threats/cve-2026-62108-headless-single-sign-on-broken-authentication-bypass"},{"cve":"CVE-2026-15981","cvss":9.8,"slug":"cve-2026-15981-miniorange-saml-single-sign-on-authentication-bypass-in-sso-login","title":"miniOrange SAML Single Sign On authentication bypass in SSO Login plugin","severity":"critical","exploited":false,"published_at":"2026-07-23T21:17:03.22+00:00","url":"https://junglewise.ai/threats/cve-2026-15981-miniorange-saml-single-sign-on-authentication-bypass-in-sso-login"},{"cve":"CVE-2026-15013","cvss":9.8,"slug":"cve-2026-15013-miniorange-saml-single-sign-on-authentication-bypass-via","title":"miniOrange SAML Single Sign On authentication bypass via algorithm confusion","severity":"critical","exploited":false,"published_at":"2026-07-16T05:16:18.043+00:00","url":"https://junglewise.ai/threats/cve-2026-15013-miniorange-saml-single-sign-on-authentication-bypass-via"},{"cve":"CVE-2026-57807","cvss":9.8,"slug":"cve-2026-57807-miniorange-oauth-single-sign-on-authentication-bypass-in-oauth","title":"miniOrange OAuth Single Sign On authentication bypass in OAuth Client","severity":"critical","exploited":false,"published_at":"2026-07-10T21:16:59.947+00:00","url":"https://junglewise.ai/threats/cve-2026-57807-miniorange-oauth-single-sign-on-authentication-bypass-in-oauth"},{"cve":"CVE-2026-12761","cvss":9.8,"slug":"cve-2026-12761-miniorange-social-login-and-register-authentication-bypass-in","title":"miniOrange Social Login and Register authentication bypass in Profile Completion flow","severity":"critical","exploited":false,"published_at":"2026-07-10T21:16:53.16+00:00","url":"https://junglewise.ai/threats/cve-2026-12761-miniorange-social-login-and-register-authentication-bypass-in"},{"cve":"CVE-2026-14245","cvss":9.8,"slug":"cve-2026-14245-miniorange-otp-login-authentication-bypass-in-ultimate-member","title":"miniOrange OTP Login authentication bypass in Ultimate Member reset hook","severity":"critical","exploited":false,"published_at":"2026-07-09T08:16:46.933+00:00","url":"https://junglewise.ai/threats/cve-2026-14245-miniorange-otp-login-authentication-bypass-in-ultimate-member"},{"cve":"CVE-2026-42731","cvss":9.8,"slug":"cve-2026-42731-miniorange-otp-verification-privilege-escalation","title":"miniOrange OTP Verification privilege escalation","severity":"critical","exploited":false,"published_at":"2026-05-27T11:16:19.6+00:00","url":"https://junglewise.ai/threats/cve-2026-42731-miniorange-otp-verification-privilege-escalation"},{"cve":"CVE-2026-8760","cvss":9.8,"slug":"cve-2026-8760-wordpress-login-with-otp-authentication-bypass-in-otpl-login","title":"WordPress Login with OTP authentication bypass in otpl_login_action","severity":"critical","exploited":false,"published_at":"2026-05-27T07:16:14.927+00:00","url":"https://junglewise.ai/threats/cve-2026-8760-wordpress-login-with-otp-authentication-bypass-in-otpl-login"},{"cve":"CVE-2026-82843","cvss":9,"epss":0.0019,"slug":"cve-2026-82843-the-wp-oauth-server-login-with-wordpress-wordpress-plugin-before","title":"WP OAuth Server OpenID Connect identity assertion binding bypass","severity":"critical","exploited":false,"published_at":"2026-09-23T06:17:02.363+00:00","url":"https://junglewise.ai/threats/cve-2026-82843-the-wp-oauth-server-login-with-wordpress-wordpress-plugin-before"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"miniOrange 2FA","slug":"2fa","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/2fa"},{"name":"miniOrange SAML Single Sign On – SSO Login","slug":"saml-single-sign-on-sso-login","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/saml-single-sign-on-sso-login"}]}