Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

miniOrange — Vulnerabilities & Security Advisories 29

Browse all 29 CVE security advisories affecting miniOrange. AI-powered Chinese analysis, POCs, and references for each vulnerability.

miniOrange primarily provides identity and access management solutions, specializing in single sign-on (SSO), multi-factor authentication (MFA), and directory synchronization for enterprise environments. Security audits have identified twenty-nine distinct Common Vulnerabilities and Exposures (CVEs) associated with its software suite, revealing a pattern of critical flaws. These vulnerabilities predominantly involve remote code execution (RCE) and cross-site scripting (XSS), allowing attackers to compromise system integrity or steal user credentials. Additionally, several instances of broken access control and privilege escalation have been documented, enabling unauthorized users to gain administrative rights. The high volume of historical CVEs suggests significant challenges in maintaining secure codebases across its diverse product offerings. While the company actively issues patches, the recurring nature of these critical flaws indicates persistent risks for organizations relying on its authentication infrastructure without rigorous security monitoring and immediate updates.

Found 2 results / 29Clear Filters

This page lists every published CVE security advisory associated with miniOrange. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.