Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-49284 SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does… Simplesamlphp 2.4.7 / 2.5.2+ Fix from $1,9502026-07-17 MEDIUM 6.1 CVE-2025-65954 SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logou… Simplesamlphp Module Casserver 6.3.1+ Fix from $1,6002026-05-18 HIGH 8.2 CVE-2026-32600 xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-… Xml Security 1.13.9 / 2.3.1+ Fix from $1,9502026-03-16 HIGH 7.5 CVE-2023-49087 xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of … Saml2 Patch available Fix from $1,9502023-11-30 MEDIUM 5.4 CVE-2010-10008 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in simplesamlphp simplesamlphp-module-openidprovider up to 0.8.x. It has been declared as p… Simplesamlphp Module Openidprovider 0.9.0+ Fix from $1,6002023-01-17 MEDIUM 6.1 CVE-2010-10004 A vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects some unknown processing. The… Information Cards Module 2010-07-29+ Fix from $1,6002023-01-09 MEDIUM 6.1 CVE-2010-10002 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an… Simplesamlphp Module Openid 1.0+ Fix from $1,6002023-01-01 MEDIUM 5.4 CVE-2020-5226 Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the syste… Simplesamlphp 1.18.4+ Fix from $1,6002020-01-24 MEDIUM 5.4 CVE-2020-5225 Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the sys… Simplesamlphp 1.18.4+ Fix from $1,6002020-01-24 HIGH 7.5 CVE-2018-7644 The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a rem… Simplesamlphp 1.15.3+ Fix from $1,9502018-03-05 MEDIUM 6.1 CVE-2018-6520 SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL. Simplesamlphp 1.15.1+ Fix from $1,6002018-02-02 MEDIUM 5.9 CVE-2017-12871 The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to b… Simplesamlphp Patch available Fix from $1,6002017-09-01 CRITICAL 9.8 CVE-2017-12868 The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to … Simplesamlphp after 1.14.13 Fix from $2,3002017-09-01 MEDIUM 5.9 CVE-2017-12870 SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt … Simplesamlphp after 1.14.12 Fix from $1,6002017-09-01 MEDIUM 5.9 CVE-2017-12867 The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity… Simplesamlphp after 1.14.14 Fix from $1,6002017-08-29 CRITICAL 9.1 CVE-2016-9814 The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.1… Simplesamlphp after 1.14.9 Fix from $2,3002017-02-17 MEDIUM 5.3 CVE-2016-3124 The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors. Simplesamlphp after 1.14.0 Fix from $1,6002017-02-07