Simplesamlphp/simplesamlphp
This hub aggregates every CVE we track for Simplesamlphp/simplesamlphp, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
3
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM10HIGH3CRITICAL3LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Simplesamlphp/simplesamlphp.
- CVE-2020-5301Information disclosure of source code in SimpleSAMLphp3.0
- CVE-2020-5226Cross-site scripting in SimpleSAMLphp4.4
- CVE-2020-5225Log injection in SimpleSAMLphp4.4
- CVE-2011-4625simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.7.5
- CVE-2017-18122A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more ...8.1
- CVE-2017-18121The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the vict...6.1
- CVE-2018-6520SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.6.1
- CVE-2018-6521The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows re...9.8
- CVE-2017-12873SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID gene...9.8
- CVE-2017-12871The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by lev...5.9
- CVE-2017-12872The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by...5.9
- CVE-2017-12869The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php vi...7.5
- CVE-2017-12868The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly byp...9.8
- CVE-2017-12870SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/C...5.9
- CVE-2017-12867The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.5.9
Product normalization is registry-driven with AI assist and human review. How it works