Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-42280 Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return u… Auth0.js 10.0.0+ Fix from $1,9502026-05-27 MEDIUM 5.4 CVE-2026-40155 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requ… Nextjs Auth0 4.18.0+ Fix from $1,6002026-04-17 CRITICAL 9.8 CVE-2026-34236 Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth… Auth0 Php 8.19.0+ Fix from $2,3002026-04-01 HIGH 7.5 CVE-2025-68129 Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access … Laravel Auth0 5.5.0 / 5.6.0+ Fix from $1,9502025-12-17 MEDIUM 5.7 CVE-2025-67716 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-valid… Nextjs Auth0 4.12.1+ Fix from $1,6002025-12-11 MEDIUM 5.4 CVE-2025-67490 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0… Nextjs Auth0 Patch available Fix from $1,6002025-12-10 HIGH 7.5 CVE-2025-65945 auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper si… Node Jws 3.2.3+ Fix from $1,9502025-12-04 HIGH 8.1 CVE-2022-23539 Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For examp… Jsonwebtoken after 8.5.1 Fix from $1,9502022-12-23 HIGH 7.6 CVE-2022-23540 In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass … Jsonwebtoken after 8.5.1 Fix from $1,9502022-12-22 MEDIUM 6.3 CVE-2022-23541 jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly imp… Jsonwebtoken after 8.5.1 Fix from $1,6002022-12-22 HIGH 7.5 CVE-2022-23505 Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker… Passport Wsfed Saml2 after 4.6.2 Fix from $1,9502022-12-13 MEDIUM 6.1 CVE-2022-29172 Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Sal… Lock 11.33.0+ Fix from $1,6002022-05-05 MEDIUM 6.1 CVE-2022-24794 Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middle… Express Openid Connect 2.7.2+ Fix from $1,6002022-03-31 MEDIUM 6.1 CVE-2021-43812 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain retu… Nextjs Auth0 1.6.2+ Fix from $1,6002021-12-16 HIGH 8.8 CVE-2021-41246 Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1`… Express Openid Connect 2.5.2+ Fix from $1,9502021-12-09 MEDIUM 6.1 CVE-2021-32702 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable… Nextjs Auth0 1.4.2+ Fix from $1,6002021-06-25 MEDIUM 6.1 CVE-2021-32641 auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execut… Lock 11.30.1+ Fix from $1,6002021-06-04 HIGH 8.8 CVE-2020-15259 ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or c… Ad\/ldap Connector 5.0.13+ Fix from $1,9502020-11-06 CRITICAL 9.1 CVE-2020-15240 omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Imp… Omniauth Auth0 2.4.1+ Fix from $2,3002020-10-21 MEDIUM 5.4 CVE-2020-15119 In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the app… Lock after 11.25.1 Fix from $1,6002020-08-20 HIGH 7.7 CVE-2020-15125 In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error ob… Auth0.js 2.27.1+ Fix from $1,9502020-07-29 CRITICAL 9.1 CVE-2020-15084 In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When al… Express Jwt after 5.3.3 Fix from $2,3002020-06-30 CRITICAL 9.8 CVE-2020-7947 An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from dif… Login By Auth0 4.0.0+ Fix from $2,3002020-04-01 HIGH 8.8 CVE-2020-5391 Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field. Wp Auth0 4.0.0+ Fix from $1,9502020-04-01 HIGH 8.8 CVE-2020-7948 An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference. Login By Auth0 4.0.0+ Fix from $1,9502020-04-01 MEDIUM 6.1 CVE-2020-5392 A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page. Wp Auth0 4.0.0+ Fix from $1,6002020-04-01 MEDIUM 6.1 CVE-2020-6753 The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392. Login By Auth0 4.0.0+ Fix from $1,6002020-04-01 MEDIUM 6.1 CVE-2019-20173 The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php. Login By Auth0 3.11.3+ Fix from $1,6002020-02-05 MEDIUM 6.1 CVE-2019-20174 Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder. Lock 11.21.0+ Fix from $1,6002020-02-03 HIGH 7.5 CVE-2019-16929 Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens. Auth0.net after 6.5.3 Fix from $1,9502019-10-08