auth0 records
41 published records for vendor auth0.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 80.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-287 Improper Authentication6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-863 Incorrect Authorization3
- CWE-20 Improper Input Validation2
- CWE-209 Generation of Error Message Containing Sensitive Information2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2015-9235Proof of concept | In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetauth0 · jsonwebtoken · CWE-20 | Critical9.8 | — | 8.7% | May 29, 2018 |
40Plan | CVE-2020-7947No exploit | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.auth0 · login by auth0 · CWE-1236 | Critical9.8 | — | 2.8% | Apr 1, 2020 |
40Plan | CVE-2018-6873No exploit | The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.auth0 · auth0.js · CWE-287 | Critical9.8 | — | 2.2% | Apr 4, 2018 |
40Plan | CVE-2019-7644No exploit | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT sauth0 · auth0-wcf-service-jwt · CWE-209 | Critical9.8 | — | 1.7% | Apr 11, 2019 |
39Monitor | CVE-2026-34236No exploit | Auth0 PHP SDK Insufficient Entropy in Cookie Encryptionauth0 · auth0-php · CWE-331 | Critical9.8 | — | 0.3% | Apr 1, 2026 |
36Monitor | CVE-2020-7948No exploit | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.auth0 · login by auth0 | High8.8 | — | 2.2% | Apr 1, 2020 |
36Monitor | CVE-2020-15084No exploit | Authorization bypass in express-jwtauth0 · express-jwt · CWE-285 | Critical9.1 | — | 1.1% | Jun 30, 2020 |
36Monitor | CVE-2020-15240No exploit | Regression in JWT Signature Validationauth0 · omniauth-auth0 · CWE-287 | Critical9.1 | — | 0.8% | Oct 21, 2020 |
35Monitor | CVE-2020-15259No exploit | CSRF in Auth0 ad-ldap-connectorauth0 · ad\/ldap connector · CWE-352 | High8.8 | — | 1.0% | Nov 6, 2020 |
35Monitor | CVE-2021-41246No exploit | Session fixation in express-openid-connectauth0 · express openid connect · CWE-384 | High8.8 | — | 0.9% | Dec 9, 2021 |
35Monitor | CVE-2020-5391No exploit | Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.auth0 · wp-auth0 · CWE-352 | High8.8 | — | 0.8% | Apr 1, 2020 |
35Monitor | CVE-2018-6874No exploit | CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.auth0 · auth0.js · CWE-352 | High8.8 | — | 0.7% | Apr 4, 2018 |
35Monitor | CVE-2018-7307No exploit | The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.auth0 · auth0.js · CWE-352 | High8.8 | — | 0.5% | Mar 6, 2018 |
35Monitor | CVE-2018-15121No exploit | An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin.auth0 · aspnet · CWE-352 | High8.8 | — | 0.5% | Aug 28, 2018 |
32Monitor | CVE-2017-16897No exploit | A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.auth0 · passport-wsfed-saml2 · CWE-290 | High8.1 | — | 1.4% | Dec 27, 2017 |
32Monitor | CVE-2022-23539No exploit | jsonwebtoken unrestricted key type could lead to legacy keys usageauth0 · jsonwebtoken · CWE-327 | High8.1 | — | 0.5% | Dec 22, 2022 |
30Monitor | CVE-2020-15125No exploit | Authorization header is not sanitized in an error object in auth0auth0 · auth0.js · CWE-209 | High7.7 | — | 1.5% | Jul 29, 2020 |
30Monitor | CVE-2017-17068No exploit | A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12.auth0 · auth0.js · CWE-200 | High7.5 | — | 1.4% | Dec 6, 2017 |
30Monitor | CVE-2019-16929No exploit | Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tauth0 · auth0.net · CWE-287 | High7.5 | — | 0.9% | Oct 8, 2019 |
30Monitor | CVE-2022-23505No exploit | Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationauth0 · passport-wsfed-saml2 · CWE-287 | High7.5 | — | 0.8% | Dec 13, 2022 |
30Monitor | CVE-2022-23540No exploit | jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()auth0 · jsonwebtoken · CWE-287 | High7.6 | — | 0.5% | Dec 22, 2022 |
30Monitor | CVE-2025-68129No exploit | Auth0-PHP SDK has Improper Audience Validationauth0 · auth0-php · CWE-863 | High7.5 | — | 0.4% | Dec 17, 2025 |
30Monitor | CVE-2025-65945Proof of concept | auth0/node-jws improper HMAC signature verification vulnerabilityauth0 · node-jws · CWE-347 | High7.5 | — | 0.2% | Dec 4, 2025 |
29Monitor | CVE-2019-13483No exploit | Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.auth0 · passport-sharepoint · CWE-345 | High7.3 | — | 0.6% | Jul 25, 2019 |
28Monitor | CVE-2026-42280No exploit | Improper Permission Checking in Auth.js SDKauth0 · auth0.js · CWE-863 | High7.1 | — | 0.3% | May 27, 2026 |
- CVE-2015-923542Plan
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmet
CriticalCVSS 9.8Proof of conceptEPSS 9%auth0 · jsonwebtokenMay 29, 2018
- CVE-2020-794740Plan
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
CriticalCVSS 9.8No exploitEPSS 3%auth0 · login by auth0Apr 1, 2020
- CVE-2018-687340Plan
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
CriticalCVSS 9.8No exploitEPSS 2%auth0 · auth0.jsApr 4, 2018
- CVE-2019-764440Plan
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s
CriticalCVSS 9.8No exploitEPSS 2%auth0 · auth0-wcf-service-jwtApr 11, 2019
- CVE-2026-3423639Monitor
Auth0 PHP SDK Insufficient Entropy in Cookie Encryption
CriticalCVSS 9.8No exploitEPSS 0%auth0 · auth0-phpApr 1, 2026
- CVE-2020-794836Monitor
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
HighCVSS 8.8No exploitEPSS 2%auth0 · login by auth0Apr 1, 2020
- CVE-2020-1508436Monitor
Authorization bypass in express-jwt
CriticalCVSS 9.1No exploitEPSS 1%auth0 · express-jwtJun 30, 2020
- CVE-2020-1524036Monitor
Regression in JWT Signature Validation
CriticalCVSS 9.1No exploitEPSS 1%auth0 · omniauth-auth0Oct 21, 2020
- CVE-2020-1525935Monitor
CSRF in Auth0 ad-ldap-connector
HighCVSS 8.8No exploitEPSS 1%auth0 · ad\/ldap connectorNov 6, 2020
- CVE-2021-4124635Monitor
Session fixation in express-openid-connect
HighCVSS 8.8No exploitEPSS 1%auth0 · express openid connectDec 9, 2021
- CVE-2020-539135Monitor
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
HighCVSS 8.8No exploitEPSS 1%auth0 · wp-auth0Apr 1, 2020
- CVE-2018-687435Monitor
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
HighCVSS 8.8No exploitEPSS 1%auth0 · auth0.jsApr 4, 2018
- CVE-2018-730735Monitor
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
HighCVSS 8.8No exploitEPSS 1%auth0 · auth0.jsMar 6, 2018
- CVE-2018-1512135Monitor
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin.
HighCVSS 8.8No exploitEPSS 0%auth0 · aspnetAug 28, 2018
- CVE-2017-1689732Monitor
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.
HighCVSS 8.1No exploitEPSS 1%auth0 · passport-wsfed-saml2Dec 27, 2017
- CVE-2022-2353932Monitor
jsonwebtoken unrestricted key type could lead to legacy keys usage
HighCVSS 8.1No exploitEPSS 0%auth0 · jsonwebtokenDec 22, 2022
- CVE-2020-1512530Monitor
Authorization header is not sanitized in an error object in auth0
HighCVSS 7.7No exploitEPSS 2%auth0 · auth0.jsJul 29, 2020
- CVE-2017-1706830Monitor
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12.
HighCVSS 7.5No exploitEPSS 1%auth0 · auth0.jsDec 6, 2017
- CVE-2019-1692930Monitor
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID t
HighCVSS 7.5No exploitEPSS 1%auth0 · auth0.netOct 8, 2019
- CVE-2022-2350530Monitor
Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authentication
HighCVSS 7.5No exploitEPSS 1%auth0 · passport-wsfed-saml2Dec 13, 2022
- CVE-2022-2354030Monitor
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
HighCVSS 7.6No exploitEPSS 1%auth0 · jsonwebtokenDec 22, 2022
- CVE-2025-6812930Monitor
Auth0-PHP SDK has Improper Audience Validation
HighCVSS 7.5No exploitEPSS 0%auth0 · auth0-phpDec 17, 2025
- CVE-2025-6594530Monitor
auth0/node-jws improper HMAC signature verification vulnerability
HighCVSS 7.5Proof of conceptEPSS 0%auth0 · node-jwsDec 4, 2025
- CVE-2019-1348329Monitor
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.
HighCVSS 7.3No exploitEPSS 1%auth0 · passport-sharepointJul 25, 2019
- CVE-2026-4228028Monitor
Improper Permission Checking in Auth.js SDK
HighCVSS 7.1No exploitEPSS 0%auth0 · auth0.jsMay 27, 2026