← Back

Auth0

auth0

41 CVEs • 21 products

Products (21)

Click to collapse
Toggle
Auth0.js
auth0.js
Nextjs Auth0
nextjs-auth0
Jsonwebtoken
jsonwebtoken
Lock
lock
Wp Auth0
wp-auth0
Auth0 Php
auth0-php
Angular Jwt
angular-jwt
Aspnet
aspnet
Aspnet Owin
aspnet-owin
Auth0.net
auth0.net
Express Jwt
express-jwt
Omniauth Auth0
omniauth-auth0
Laravel Auth0
laravel-auth0
Symfony
symfony
Node Jws
node-jws

CVEs (41)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Auth0
1Auth0.js
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in...Show more
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management APIShow less
1Auth0
1Express Jwt
Jun 17, 2026
Jun 30, 2020
N/A· v4
9.1 CRITICAL· v3
4.3 MEDIUM· v2
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of...Show more
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of the following conditions apply: - You are using express-jwt - You do not have **algorithms** configured in your express-jwt configuration. - You are using libraries such as jwks-rsa as the **secret**. You can fix this by specifying **algorithms** in the express-jwt configuration. See linked GHSA for example. This is also fixed in version 6.0.0.Show less
1Auth0
1Auth0.js
Jun 17, 2026
Apr 9, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request o...Show more
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the user entered. If the error object is exposed or logged without modification, the application risks password exposure. This is fixed in version 9.12.3Show less
1Auth0
1Login By Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.
1Auth0
1Login By Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, a...Show more
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.Show less
1Auth0
1Login By Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.
1Auth0
1Wp Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.
1Auth0
1Wp Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
1Auth0
1Login By Auth0
Jun 17, 2026
Feb 5, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
1Auth0
1Lock
Jun 17, 2026
Feb 3, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
1Auth0
1Auth0.net
Jun 17, 2026
Oct 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
1Auth0
1Passport Sharepoint
Jun 17, 2026
Jul 25, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
1Auth0
1Auth0 Wcf Service Jwt
Jun 17, 2026
Apr 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an a...Show more
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.Show less
1Auth0
2Aspnet
Aspnet Owin
Nov 21, 2024
Aug 29, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF...Show more
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.Show less
1Auth0
1Angular Jwt
Nov 21, 2024
Jun 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whiteli...Show more
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.Show less
1Auth0
1Jsonwebtoken
Nov 21, 2024
May 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digit...Show more
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).Show less
1Auth0
1Auth0.js
Jun 17, 2026
Apr 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
1Auth0
1Auth0.js
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
1Auth0
1Auth0.js
Jun 17, 2026
Mar 6, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
1Auth0
1Passport Wsfed Saml2
May 13, 2026
Dec 27, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the...Show more
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).Show less