CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-49289 HIGH

SimpleSAMLphp SAML2: Possible DoS via XPath Transform

CVSS 7.5 EPSS 0.78% Aug 19, 2026
CVE-2026-49283 HIGH

SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass

CVSS 8.7 EPSS 0.47% Aug 19, 2026
CVE-2026-49284 HIGH

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmati…

CVSS 7.1 EPSS 0.22% Jul 17, 2026
CVE-2026-46491 HIGH

SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion

CVSS 8.6 EPSS 0.62% Jun 9, 2026
CVE-2025-65954 MEDIUM

SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

CVSS 6.1 EPSS 0.27% May 18, 2026
CVE-2026-32600 HIGH

xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

CVSS 8.2 EPSS 0.17% Mar 13, 2026
CVE-2025-27773 HIGH

SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding

CVSS 8.6 EPSS 0.39% Mar 11, 2025
CVE-2024-52596 HIGH

SimpleSAMLphp xml-common XXE vulnerability

CVSS 8.8 EPSS 0.98% Dec 2, 2024
CVE-2024-52806 MEDIUM

SimpleSAMLphp SAML2 has an XXE in parsing SAML messages

CVSS 6.9 EPSS 0.43% Dec 2, 2024
CVE-2024-34580 MEDIUM

Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload…

CVSS 5.3 EPSS 0.21% Jun 26, 2024
CVE-2023-49087 HIGH

Validation of SignedInfo

CVSS 7.5 EPSS 0.19% Nov 30, 2023
CVE-2010-10008 MEDIUM

simplesamlphp simplesamlphp-module-openidprovider trust.tpl.php cross site scripting

CVSS 5.4 EPSS 0.56% Jan 17, 2023
CVE-2010-10004 MEDIUM

Information Cards Module cross site scripting

CVSS 6.1 EPSS 0.51% Jan 9, 2023
CVE-2010-10002 MEDIUM

SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scripting

CVSS 6.1 EPSS 0.64% Jan 1, 2023
CVE-2020-5301 LOW

Information disclosure of source code in SimpleSAMLphp

CVSS 3.1 EPSS 0.92% Apr 21, 2020
CVE-2020-5226 MEDIUM

Cross-site scripting in SimpleSAMLphp

CVSS 5.4 EPSS 0.54% Jan 24, 2020
CVE-2020-5225 MEDIUM

Log injection in SimpleSAMLphp

CVSS 5.4 EPSS 0.66% Jan 24, 2020
CVE-2019-3465 HIGH

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML…

CVSS 8.8 EPSS 2.99% Nov 7, 2019
CVE-2011-4625 HIGH

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

CVSS 7.5 EPSS 0.74% Nov 6, 2019
CVE-2018-7711 HIGH

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an…

CVSS 8.1 EPSS 1.19% Mar 5, 2018
CVE-2018-7644 HIGH

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attack…

CVSS 7.5 EPSS 1.25% Mar 5, 2018
CVE-2017-18122 HIGH

A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any u…

CVSS 8.1 EPSS 1.09% Feb 2, 2018
CVE-2017-18121 MEDIUM

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute…

CVSS 6.1 EPSS 1.20% Feb 2, 2018
CVE-2018-6521 CRITICAL

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might…

CVSS 9.8 EPSS 3.05% Feb 2, 2018
CVE-2018-6520 MEDIUM

SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.

CVSS 6.1 EPSS 0.85% Feb 2, 2018

Showing 1 to 25 CVEs · page 1 (more available)