Skip to content
Noroxi

2fauth records

5 published records for vendor 2fauth.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
40%
Median publish → KEV
No record has entered KEV

All records

5 records
  • 2FAuth has Blind SSRF in image parameter allows internal network access and more

    HighCVSS 7.8No exploitEPSS 1%

    2fauth · 2fauthMar 11, 2026

  • 2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview

    HighCVSS 7.5No exploitEPSS 1%

    2fauth · 2fauthNov 20, 2024

  • A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other opera

    MediumCVSS 6.5No exploitEPSS 0%

    2fauth · 2fauthJul 24, 2025

  • Cross-Site Scripting (XSS) at Account creation in 2FAuth

    MediumCVSS 6.1No exploitEPSS 0%

    2fauth · 2fauthJul 3, 2023

  • 2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render

    MediumCVSS 6.1No exploitEPSS 0%

    2fauth · 2fauthNov 20, 2024