VYPR

Vendor CVEs

Auth0

All CVEs

50 total · sorted by risk
  • CVE-2020-7947CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting…

  • CVE-2019-7644CriApr 11, 2019
    risk 0.64cvss 9.8epss 0.02

    Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable…

  • CVE-2018-6873CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

  • CVE-2020-7948HigApr 1, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.

  • CVE-2018-15121HigAug 29, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.

  • CVE-2015-9235CriMay 29, 2018
    risk 0.57cvss 9.8epss 0.09

    In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

  • CVE-2018-6874HigApr 4, 2018
    risk 0.57cvss 8.8epss 0.01

    CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

  • CVE-2018-7307HigMar 6, 2018
    risk 0.57cvss 8.8epss 0.01

    The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.

  • CVE-2025-48951CriJun 3, 2025
    risk 0.54cvss epss 0.01

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could…

  • CVE-2025-46572CriMay 6, 2025
    risk 0.53cvss epss 0.00

    passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by crafting a SAMLResponse. This can be…

  • CVE-2025-47275CriMay 15, 2025
    risk 0.52cvss 9.1epss 0.01

    Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using the Auth0-PHP SDK configured with CookieStore have authentication tags that can be brute forced, which…

  • CVE-2020-5391HigApr 1, 2020
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

  • CVE-2025-46573HigMay 6, 2025
    risk 0.49cvss epss 0.00

    passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by tampering with a valid SAML response.…

  • CVE-2019-16929HigOct 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.

  • CVE-2017-17068HigDec 6, 2017
    risk 0.49cvss 7.5epss 0.01

    A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback…

  • CVE-2019-13483HigJul 25, 2019
    risk 0.47cvss 7.3epss 0.01

    Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.

  • CVE-2026-42280HigMay 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is…

  • CVE-2026-34236HigApr 1, 2026
    risk 0.46cvss 8.2epss 0.00

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and…

  • CVE-2021-32641HigJun 4, 2021
    risk 0.46cvss 8.1epss 0.02

    auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated…

  • CVE-2017-16897HigDec 27, 2017
    risk 0.46cvss 8.1epss 0.01

    A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response…

  • CVE-2021-32702HigJun 25, 2021
    risk 0.45cvss 8.0epss 0.01

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the `error` query parameter which is then…

  • CVE-2025-48947HigJun 4, 2025
    risk 0.43cvss epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers. Three preconditions must be…

  • CVE-2020-15084HigJun 30, 2020
    risk 0.43cvss 7.7epss 0.01

    In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are…

  • CVE-2025-65945HigDec 4, 2025
    risk 0.42cvss 7.5epss 0.00

    auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they…

  • CVE-2022-24794HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is…

  • CVE-2020-15240HigOct 21, 2020
    risk 0.41cvss 7.4epss 0.01

    omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT token signature can allow an attacker to bypass authentication and authorization. You are affected by…

  • CVE-2023-6813MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2020-6753MedApr 1, 2020
    risk 0.40cvss 6.1epss 0.01

    The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.

  • CVE-2019-20173MedFeb 5, 2020
    risk 0.40cvss 6.1epss 0.02

    The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

  • CVE-2025-46345MedMay 1, 2025
    risk 0.38cvss epss 0.00

    Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper…

  • CVE-2025-68129MedDec 17, 2025
    risk 0.37cvss 6.8epss 0.00

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects…

  • CVE-2022-23540MedDec 22, 2022
    risk 0.35cvss 6.4epss 0.01

    In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the…

  • CVE-2021-43812MedDec 16, 2021
    risk 0.35cvss 6.4epss 0.01

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability. Users are advised to…

  • CVE-2020-15119MedAug 20, 2020
    risk 0.35cvss 6.4epss 0.01

    In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.

  • CVE-2018-11537MedJun 19, 2018
    risk 0.35cvss 6.5epss 0.01

    Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.

  • CVE-2022-29172MedMay 5, 2022
    risk 0.33cvss 6.1epss 0.01

    Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `11.33.0`, when the “additional signup fields” feature [is configured](https://github.com/auth0/loc…

  • CVE-2020-5392MedApr 1, 2020
    risk 0.33cvss 6.1epss 0.01

    A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.

  • CVE-2019-20174MedFeb 3, 2020
    risk 0.33cvss 6.1epss 0.01

    Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.

  • CVE-2022-23539MedDec 23, 2022
    risk 0.31cvss 5.9epss 0.00

    Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. You are affected if you are using an algorithm and a key type other than a…

  • CVE-2025-67716MedDec 11, 2025
    risk 0.30cvss 5.7epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo parameter, which could allow attackers to inject unintended OAuth query parameters into the Auth0…

  • CVE-2020-5263MedApr 9, 2020
    risk 0.29cvss 5.5epss 0.01

    auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the…

  • CVE-2026-40155MedApr 17, 2026
    risk 0.28cvss 5.4epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. Users…

  • CVE-2025-67490MedDec 10, 2025
    risk 0.28cvss 5.4epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This…

  • CVE-2022-23541MedDec 22, 2022
    risk 0.26cvss 5.0epss 0.01

    jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval function referring to the `secretOrPublicKey` argument from the readme link will result in incorrect…

  • CVE-2025-46344MedApr 29, 2025
    risk 0.25cvss epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal…

  • CVE-2021-41246MedDec 9, 2021
    risk 0.23cvss 4.6epss 0.01

    Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session…

  • CVE-2026-50157medJul 14, 2026
    risk 0.19cvss epss

    ### Description Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may…

  • CVE-2022-23505MedDec 13, 2022
    risk 0.00cvss 5.3epss 0.01

    Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the…

  • CVE-2020-15259HigNov 6, 2020
    risk 0.00cvss 8.1epss 0.01

    ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or confidential data loss. CSRF exploits may occur if the user visits a malicious page containing CSRF payload on the same machine…

  • CVE-2020-15125HigJul 29, 2020
    risk 0.00cvss 7.7epss 0.02

    In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged…