2fauth records
5 published records for vendor 2fauth.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2026-32133No exploit | 2FAuth has Blind SSRF in image parameter allows internal network access and more2fauth · 2fauth · CWE-918 | High7.8 | — | 0.5% | Mar 11, 2026 |
30Monitor | CVE-2024-52598No exploit | 2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview2fauth · 2fauth · CWE-79 | High7.5 | — | 0.6% | Nov 20, 2024 |
26Monitor | CVE-2025-45731No exploit | A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other opera2fauth · 2fauth · CWE-362 | Medium6.5 | — | 0.3% | Jul 24, 2025 |
24Monitor | CVE-2023-36816No exploit | Cross-Site Scripting (XSS) at Account creation in 2FAuth2fauth · 2fauth · CWE-79 | Medium6.1 | — | 0.5% | Jul 3, 2023 |
24Monitor | CVE-2024-52597No exploit | 2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render2fauth · 2fauth · CWE-79 | Medium6.1 | — | 0.4% | Nov 20, 2024 |
- CVE-2026-3213331Monitor
2FAuth has Blind SSRF in image parameter allows internal network access and more
HighCVSS 7.8No exploitEPSS 1%2fauth · 2fauthMar 11, 2026
- CVE-2024-5259830Monitor
2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview
HighCVSS 7.5No exploitEPSS 1%2fauth · 2fauthNov 20, 2024
- CVE-2025-4573126Monitor
A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other opera
MediumCVSS 6.5No exploitEPSS 0%2fauth · 2fauthJul 24, 2025
- CVE-2023-3681624Monitor
Cross-Site Scripting (XSS) at Account creation in 2FAuth
MediumCVSS 6.1No exploitEPSS 0%2fauth · 2fauthJul 3, 2023
- CVE-2024-5259724Monitor
2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render
MediumCVSS 6.1No exploitEPSS 0%2fauth · 2fauthNov 20, 2024