Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Auth0.js HIGH 7.1
CVE-2026-42280

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return u…

Fix: 10.0.0+
Fix from $1,950 2026-05-27
Nextjs Auth0 MEDIUM 5.4
CVE-2026-40155

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requ…

Fix: 4.18.0+
Fix from $1,600 2026-04-17
Auth0 Php CRITICAL 9.8
CVE-2026-34236

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth…

Fix: 8.19.0+
Fix from $2,300 2026-04-01
Laravel Auth0 HIGH 7.5
CVE-2025-68129

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access …

Fix: 5.5.0 / 5.6.0+
Fix from $1,950 2025-12-17
Nextjs Auth0 MEDIUM 5.7
CVE-2025-67716

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-valid…

Fix: 4.12.1+
Fix from $1,600 2025-12-11
Nextjs Auth0 MEDIUM 5.4
CVE-2025-67490

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0…

Patch available
Fix from $1,600 2025-12-10
Node Jws HIGH 7.5
CVE-2025-65945

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper si…

Fix: 3.2.3+
Fix from $1,950 2025-12-04
Jsonwebtoken HIGH 8.1
CVE-2022-23539

Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For examp…

Fix: after 8.5.1
Fix from $1,950 2022-12-23
Jsonwebtoken HIGH 7.6
CVE-2022-23540

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass …

Fix: after 8.5.1
Fix from $1,950 2022-12-22
Jsonwebtoken MEDIUM 6.3
CVE-2022-23541

jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly imp…

Fix: after 8.5.1
Fix from $1,600 2022-12-22
Passport Wsfed Saml2 HIGH 7.5
CVE-2022-23505

Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker…

Fix: after 4.6.2
Fix from $1,950 2022-12-13
Lock MEDIUM 6.1
CVE-2022-29172

Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Sal…

Fix: 11.33.0+
Fix from $1,600 2022-05-05
Express Openid Connect MEDIUM 6.1
CVE-2022-24794

Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middle…

Fix: 2.7.2+
Fix from $1,600 2022-03-31
Nextjs Auth0 MEDIUM 6.1
CVE-2021-43812

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain retu…

Fix: 1.6.2+
Fix from $1,600 2021-12-16
Express Openid Connect HIGH 8.8
CVE-2021-41246

Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1`…

Fix: 2.5.2+
Fix from $1,950 2021-12-09
Nextjs Auth0 MEDIUM 6.1
CVE-2021-32702

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable…

Fix: 1.4.2+
Fix from $1,600 2021-06-25
Lock MEDIUM 6.1
CVE-2021-32641

auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execut…

Fix: 11.30.1+
Fix from $1,600 2021-06-04
Ad\/ldap Connector HIGH 8.8
CVE-2020-15259

ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or c…

Fix: 5.0.13+
Fix from $1,950 2020-11-06
Omniauth Auth0 CRITICAL 9.1
CVE-2020-15240

omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Imp…

Fix: 2.4.1+
Fix from $2,300 2020-10-21
Lock MEDIUM 5.4
CVE-2020-15119

In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the app…

Fix: after 11.25.1
Fix from $1,600 2020-08-20
Auth0.js HIGH 7.7
CVE-2020-15125

In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error ob…

Fix: 2.27.1+
Fix from $1,950 2020-07-29
Express Jwt CRITICAL 9.1
CVE-2020-15084

In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When al…

Fix: after 5.3.3
Fix from $2,300 2020-06-30
Login By Auth0 CRITICAL 9.8
CVE-2020-7947

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from dif…

Fix: 4.0.0+
Fix from $2,300 2020-04-01
Wp Auth0 HIGH 8.8
CVE-2020-5391

Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

Fix: 4.0.0+
Fix from $1,950 2020-04-01
Login By Auth0 HIGH 8.8
CVE-2020-7948

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.

Fix: 4.0.0+
Fix from $1,950 2020-04-01
Wp Auth0 MEDIUM 6.1
CVE-2020-5392

A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.

Fix: 4.0.0+
Fix from $1,600 2020-04-01
Login By Auth0 MEDIUM 6.1
CVE-2020-6753

The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.

Fix: 4.0.0+
Fix from $1,600 2020-04-01
Login By Auth0 MEDIUM 6.1
CVE-2019-20173

The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

Fix: 3.11.3+
Fix from $1,600 2020-02-05
Lock MEDIUM 6.1
CVE-2019-20174

Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.

Fix: 11.21.0+
Fix from $1,600 2020-02-03
Auth0.net HIGH 7.5
CVE-2019-16929

Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.

Fix: after 6.5.3
Fix from $1,950 2019-10-08