Skip to content
Noroxi

auth0 records

41 published records for vendor auth0.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
80.5%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

41 records
  • In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmet

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    auth0 · jsonwebtokenMay 29, 2018

  • An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.

    CriticalCVSS 9.8No exploitEPSS 3%

    auth0 · login by auth0Apr 1, 2020

  • The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

    CriticalCVSS 9.8No exploitEPSS 2%

    auth0 · auth0.jsApr 4, 2018

  • Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s

    CriticalCVSS 9.8No exploitEPSS 2%

    auth0 · auth0-wcf-service-jwtApr 11, 2019

  • Auth0 PHP SDK Insufficient Entropy in Cookie Encryption

    CriticalCVSS 9.8No exploitEPSS 0%

    auth0 · auth0-phpApr 1, 2026

  • CVE-2020-7948
    36Monitor

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.

    HighCVSS 8.8No exploitEPSS 2%

    auth0 · login by auth0Apr 1, 2020

  • Authorization bypass in express-jwt

    CriticalCVSS 9.1No exploitEPSS 1%

    auth0 · express-jwtJun 30, 2020

  • Regression in JWT Signature Validation

    CriticalCVSS 9.1No exploitEPSS 1%

    auth0 · omniauth-auth0Oct 21, 2020

  • CSRF in Auth0 ad-ldap-connector

    HighCVSS 8.8No exploitEPSS 1%

    auth0 · ad\/ldap connectorNov 6, 2020

  • Session fixation in express-openid-connect

    HighCVSS 8.8No exploitEPSS 1%

    auth0 · express openid connectDec 9, 2021

  • CVE-2020-5391
    35Monitor

    Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

    HighCVSS 8.8No exploitEPSS 1%

    auth0 · wp-auth0Apr 1, 2020

  • CVE-2018-6874
    35Monitor

    CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

    HighCVSS 8.8No exploitEPSS 1%

    auth0 · auth0.jsApr 4, 2018

  • CVE-2018-7307
    35Monitor

    The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.

    HighCVSS 8.8No exploitEPSS 1%

    auth0 · auth0.jsMar 6, 2018

  • An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin.

    HighCVSS 8.8No exploitEPSS 0%

    auth0 · aspnetAug 28, 2018

  • A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.

    HighCVSS 8.1No exploitEPSS 1%

    auth0 · passport-wsfed-saml2Dec 27, 2017

  • jsonwebtoken unrestricted key type could lead to legacy keys usage

    HighCVSS 8.1No exploitEPSS 0%

    auth0 · jsonwebtokenDec 22, 2022

  • Authorization header is not sanitized in an error object in auth0

    HighCVSS 7.7No exploitEPSS 2%

    auth0 · auth0.jsJul 29, 2020

  • A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12.

    HighCVSS 7.5No exploitEPSS 1%

    auth0 · auth0.jsDec 6, 2017

  • Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID t

    HighCVSS 7.5No exploitEPSS 1%

    auth0 · auth0.netOct 8, 2019

  • Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authentication

    HighCVSS 7.5No exploitEPSS 1%

    auth0 · passport-wsfed-saml2Dec 13, 2022

  • jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()

    HighCVSS 7.6No exploitEPSS 1%

    auth0 · jsonwebtokenDec 22, 2022

  • Auth0-PHP SDK has Improper Audience Validation

    HighCVSS 7.5No exploitEPSS 0%

    auth0 · auth0-phpDec 17, 2025

  • auth0/node-jws improper HMAC signature verification vulnerability

    HighCVSS 7.5Proof of conceptEPSS 0%

    auth0 · node-jwsDec 4, 2025

  • Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.

    HighCVSS 7.3No exploitEPSS 1%

    auth0 · passport-sharepointJul 25, 2019

  • Improper Permission Checking in Auth.js SDK

    HighCVSS 7.1No exploitEPSS 0%

    auth0 · auth0.jsMay 27, 2026