CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
SimpleSAMLphp SAML2: Possible DoS via XPath Transform
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmati…
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding
SimpleSAMLphp xml-common XXE vulnerability
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload…
Validation of SignedInfo
simplesamlphp simplesamlphp-module-openidprovider trust.tpl.php cross site scripting
Information Cards Module cross site scripting
SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scripting
Information disclosure of source code in SimpleSAMLphp
Cross-site scripting in SimpleSAMLphp
Log injection in SimpleSAMLphp
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML…
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an…
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attack…
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any u…
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute…
The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might…
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
Showing 1 to 25 CVEs · page 1 (more available)