vciy

CVEs we hold for Cyberlord92

Records whose assigning authority named Cyberlord92 as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-75807SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoningcyberlord92 SAML Single Sign On – SSO Login
CVE-2026-2628All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 - Authentication Bypasscyberlord92 All-in-One Microsoft 365 & Entra ID / Azure AD…
CVE-2026-15981SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parametercyberlord92 SAML Single Sign On – SSO Login
CVE-2026-15013SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm…cyberlord92 SAML Single Sign On – SSO Login
CVE-2026-14245miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account…cyberlord92 miniOrange OTP Login, Verification and SMS…
CVE-2026-1279Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_title' Shortcode…cyberlord92 Employee Directory – Staff Directory and Listing
CVE-2026-12761miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication…cyberlord92 miniOrange Social Login and Register (Discord…
CVE-2026-12000Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST…cyberlord92 Page and Post Restriction
CVE-2026-0725Integrate Dynamics 365 CRM <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Field Mapping…cyberlord92 Integrate Dynamics 365 CRM
CVE-2025-9891User Sync – Remote User Sync <= 1.0.2 - Cross-Site Request Forgery to Plugin Deactivationcyberlord92 User Sync
CVE-2025-9485OAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Authentication Bypass via get_resource_owner_from_id_token()cyberlord92 OAuth Single Sign On – SSO (OAuth Client)
CVE-2025-7665Miniorange OTP Verification with Firebase 3.1.0 - 3.6.2 - Unauthenticated Privilege Escalationcyberlord92 Miniorange OTP Verification with Firebase
CVE-2025-6003WordPress Single Sign-On (SSO) - Multiple Versions - Incorrect Authorization to Sensitive Information Exposurecyberlord92 WordPress Single Sign-On (SSO) - Multisite…
CVE-2025-14948miniOrange OTP Verification and SMS Notification for WooCommerce <= 4.3.8 - Missing Authorization to Unauthenticated…cyberlord92 miniOrange OTP Verification and SMS…
CVE-2025-12822WP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) API Key Exposurecyberlord92 WP Login and Register using JWT
CVE-2025-11255Password Policy Manager | Password Manager <= 2.0.5 - Missing Authorization to Authenticated (Subscriber+)…cyberlord92 Password Policy Manager | Password Manager
CVE-2025-10753OAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing Authorizationcyberlord92 OAuth Single Sign On – SSO (OAuth Client)
CVE-2025-10752OAuth Single Sign On – SSO (OAuth Client) <= 6.26.12 - Cross-Site Request Forgerycyberlord92 OAuth Single Sign On – SSO (OAuth Client)
CVE-2025-10750PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosurecyberlord92 PowerBI Embed Reports
CVE-2025-10746Integrate Dynamics 365 CRM <= 1.0.9 - Missing Authorizationcyberlord92 Integrate Dynamics 365 CRM
CVE-2025-10648Login with YourMembership - YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information…cyberlord92 Login with YourMembership – YM SSO Login
CVE-2024-9887Login using WordPress Users ( WP as SAML IDP ) <= 1.15.6 - Authenticated (Administrator+) SQL Injectioncyberlord92 SAML IDP (Identity Provider) – Login with…
CVE-2024-9863Miniorange OTP Verification with Firebase <= 3.6.0 - Privilege Escalation via Registration due to Administrator Default…cyberlord92 Miniorange OTP Verification with Firebase
CVE-2024-9862Miniorange OTP Verification with Firebase <= 3.6.0 - Unauthenticated Arbitrary User Password Changecyberlord92 Miniorange OTP Verification with Firebase
CVE-2024-9861Miniorange OTP Verification with Firebase <= 3.6.0 - Authentication Bypasscyberlord92 Miniorange OTP Verification with Firebase
CVE-2024-2172Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalationcyberlord92 Malware Scanner
CVE-2024-12121Broken Link Checker | Finder <= 2.5.0 - Authenticated (Author+) Blind Server-Side Request Forgerycyberlord92 Broken Link Checker | Finder
CVE-2024-11901PowerBI Embed Reports <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scriptingcyberlord92 PowerBI Embed Reports
CVE-2024-11297Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to…cyberlord92 Page and Post Restriction
CVE-2024-11087miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypasscyberlord92 miniOrange Social Login and Register (Discord…
CVE-2024-10111OAuth Single Sign On – SSO (OAuth Client) <= 6.26.3 - Authentication Bypasscyberlord92 OAuth Single Sign On – SSO (OAuth Client)
CVE-2024-0681Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.4 - Protection Mechanism Bypasscyberlord92 Page and Post Restriction
CVE-2023-46082WordPress Broken Link Checker | Finder plugin <= 2.4.2 - Broken Access Control vulnerabilityCyberlord92 Broken Link Checker | Finder
CVE-2023-4506Active Directory Integration / LDAP Integration <= 4.1.10 - LDAP Passbackcyberlord92 Active Directory Integration / LDAP Integration
CVE-2023-4505Staff / Employee Business Directory for Active Directory <= 1.2.3 - Authenticated (Admin+) LDAP Passbackcyberlord92 Staff/Employee Business Directory for Active…
CVE-2023-3447Active Directory Integration / LDAP Integration <= 4.1.5 - Authenticated (Subscriber+) LDAP Injectioncyberlord92 Active Directory Integration / LDAP Integration
CVE-2023-3249Web3 – Crypto wallet Login & NFT token gating <= 2.6.0 - Authentication Bypasscyberlord92 Web3 – Crypto wallet Login & NFT token gating
CVE-2023-2982WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypasscyberlord92 miniOrange Social Login and Register (Discord…
CVE-2023-2599Active Directory Integration / LDAP Integration <= 4.1.4 - Cross-Site Request Forgery to SQL Injectioncyberlord92 Active Directory Integration / LDAP Integration
CVE-2023-2484Active Directory Integration / LDAP Integration <= 4.1.4 - Authenticated (Administrator+) SQL Injectioncyberlord92 Active Directory Integration / LDAP Integration
CVE-2022-4943miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Changecyberlord92 miniOrange 2FA – Two-Factor Authentication for…
CVE-2022-4539Web Application Firewall <= 2.1.2 - IP Address Spoofing to Protection Mechanism Bypasscyberlord92 Web Application Firewall – website security

42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.