simplesamlphp Summary
Latest vulnerabilities published by simplesamlphp
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
CVE-2026-46491SimplesamlPHPSimplesamlPHP-module-c...8.6HIGHVulnerability in SimpleSAMLphp-casserver for CAS 1.0 and 2.0 by SimpleSAMLphp
CVE-2025-65954SimplesamlPHPSimplesamlPHP-module-c...4.7MEDIUMXML Security Library Vulnerability in SimpleSAMLphp
CVE-2026-32600SimplesamlPHPXml-security8.2HIGHSignature Confusion Vulnerability in SimpleSAMLphp SAML2 Library
CVE-2025-27773SimplesamlPHPSaml28.6HIGHUntrusted XML Documents Can Cause XXE Vulnerability in SimpleSAMLphp xml-common
CVE-2024-52596SimplesamlPHPXml-commonFixed XXE vulnerability in SAML2 library
CVE-2024-52806SimplesamlPHPSaml28.3HIGHValidation of SignedInfo
CVE-2023-49087simplesamlphpxml-security7.5HIGHsimplesamlphp simplesamlphp-module-openidprovider trust.tpl.php cross site scripting
CVE-2010-10008SimplesamlPHPSimplesamlPHP-module-o...3.5LOWInformation Cards Module cross site scripting
CVE-2010-10004SimplesamlPHPInformation Cards Module3.5LOWSimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scripting
CVE-2010-10002SimplesamlPHPSimplesamlPHP-module-o...6.1MEDIUMsimpleSAMLphp Authentication <= 0.7.0 Reflected Cross-Site Scripting
CVE-2021-38320SimplesamlPHP Aut...SimplesamlPHP Authenti...6.1MEDIUMInformation disclosure of source code in SimpleSAMLphp
CVE-2020-5301SimplesamlPHPSimplesamlPHP3LOWCross-site scripting in SimpleSAMLphp
CVE-2020-5226SimplesamlPHPSimplesamlPHP4.4MEDIUMLog injection in SimpleSAMLphp
CVE-2020-5225SimplesamlPHPSimplesamlPHP4.4MEDIUMXML Encryption Flaw in SimpleSAMLphp Affects Multiple Versions
CVE-2011-4625SimplesamlPHPSimplesamlPHP7.5HIGHSignature Validation Vulnerability in SimpleSAMLphp Library
CVE-2018-7711SimplesamlPHPSimplesamlPHP8.1HIGHSAML Assertion Signature Verification Issue in SimpleSAMLphp
CVE-2018-7644SimplesamlPHPSimplesamlPHP7.5HIGHCross-Site Scripting Vulnerability in SimpleSAMLphp by SimpleSAML
CVE-2017-18121SimplesamlPHPSimplesamlPHP6.1MEDIUMSignature-Validation Bypass in SimpleSAMLphp by SimpleSAMLphp
CVE-2017-18122SimplesamlPHPSimplesamlPHP8.1HIGHRegular Expression Denial of Service in SimpleSAMLphp by Lasso Inc.
CVE-2018-6519SimplesamlPHPSaml27.5HIGHOpen Redirect Flaw in SimpleSAMLphp by SimpleSAML
CVE-2018-6520SimplesamlPHPSimplesamlPHP6.1MEDIUMAccess Bypass Vulnerability in SimpleSAMLphp's sqlauth Module
CVE-2018-6521SimplesamlPHPSimplesamlPHP9.8CRITICALEncryption Bypass in SimpleSAMLphp by Utilizing Initialization Vector
CVE-2017-12871SimplesamlPHPSimplesamlPHP5.9MEDIUMTiming Side-Channel Vulnerability in SimpleSAMLphp Authcrypt Module
CVE-2017-12872SimplesamlPHPSimplesamlPHP5.9MEDIUMInformation Disclosure Risk in SimpleSAMLphp by Launching Attacks on Misconfigured Identity Providers
CVE-2017-12873SimplesamlPHPSimplesamlPHP9.8CRITICAL