Auth0 / Auth0.js
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-42280 | Improper Permission Checking in Auth.js SDK | HIGH | 7.1 | May 27, 2026 |
| CVE-2020-15125 | Authorization header is not sanitized in an error object in auth0 | HIGH | 7.7 | Jul 29, 2020 |
| CVE-2020-5263 | Information disclosure through error object | HIGH | 5.5 | Apr 9, 2020 |
| CVE-2018-6874 | CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled. | HIGH | 8.8 | Apr 4, 2018 |
| CVE-2018-6873 | The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated. | CRITICAL | 9.8 | Apr 4, 2018 |
| CVE-2018-7307 | The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter. | HIGH | 8.8 | Mar 6, 2018 |
| CVE-2017-17068 | A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire auth… | HIGH | 7.5 | Dec 6, 2017 |
Showing 1 to 7 of 7 CVEs