Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
miniorange saml sp single sign on vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-12346
In the miniOrange SAML SP Single Sign On plugin prior to 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.
Miniorange Saml Sp Single Sign On
6.1
CVSSv3
CVE-2020-6850
Utilities.php in the miniorange-saml-20-single-sign-on plugin prior to 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.
Miniorange Saml Sp Single Sign On
6.1
CVSSv3
CVE-2022-4496
The SAML SSO Standard WordPress plugin version 16.0.0 prior to 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 prior to 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 prior to 20.0.7 does not validate that the redirect parameter to its SSO login en...
Miniorange Miniorange Wordpress Saml Sso Standard
Miniorange Miniorange Wordpress Saml Sso Premium
Miniorange Miniorange Wordpress Saml Sso Premium Mulsitesite
Miniorange Saml Sp Single Sign On
8.8
CVSSv3
CVE-2022-26493
Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the S...
Xecuify Drupal 8 Miniorange Saml Sp
Xecuify Drupal 9 Miniorange Saml Sp
Xecuify Drupal 7 Miniorange Saml Sp
Drupal Saml Sp 2.0 Single Sign On
4.3
CVSSv3
CVE-2023-41873
Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a up to and including 5.0.4.
Miniorange Saml Sp Single Sign On
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
jasmin ransomware
CVE-2025-6110
code execution
CVE-2025-21420
reflected XSS
CVE-2025-5336
wp url shortener
CVE-2025-49113
gr-5400ax
overflow
CVE-2025-6062
letta-ai
CVE-2025-50143
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started