simplesamlphp/simplesamlphp vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-49284Highsimplesamlphp/simplesamlphp: SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion…GHSA-PPM4-R2VC-PG74Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Information Disclosure vulnerabilityGHSA-VPR3-CW3H-PRW8Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Reflected Cross-site Scripting vulnerabilityGHSA-7WH8-JRQ7-P27FMediumsimplesamlphp/simplesamlphp: SimpleSAMLphp exposes credentials in session storageGHSA-V858-922F-FJ9VMediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Link Injection vulnerabilityCVE-2017-12871Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Incorrect IV generation for encryptionCVE-2017-12870Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Unauthenticated encryption in CBC modeCVE-2018-6520Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Open redirection protection bypassCVE-2017-12868Criticalsimplesamlphp/simplesamlphp: SimpleSAMLphp Session fixation issue and authentication bypass in the authcrypt moduleCVE-2016-3124Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Information leakage issue in the sanitycheck moduleCVE-2017-12869Highsimplesamlphp/simplesamlphp: SimpleSAMLphp Authentication context bypass in the multiauth moduleCVE-2017-18121Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp XSS VulnerabilityCVE-2017-18122Highsimplesamlphp/simplesamlphp: SimpleSAMLphp Signature validation bypassCVE-2017-12872Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp allows timing side-channel attacksCVE-2018-6521Criticalsimplesamlphp/simplesamlphp: SimpleSAMLphp Use of insecure connection charset (sqlauth module)CVE-2017-12867Mediumsimplesamlphp/simplesamlphp: SimpleSAMLphp Invalid token creation and validationCVE-2011-4625Highsimplesamlphp/simplesamlphp: simpleSAMLphp incorrectly handles XML encryptionCVE-2020-5301Lowsimplesamlphp/simplesamlphp: Information disclosure of source code in SimpleSAMLphpCVE-2017-12873Criticalsimplesamlphp/simplesamlphp: Incorrect persistent NameID generation in SimpleSAMLphpCVE-2016-9955Mediumsimplesamlphp/simplesamlphp: Incorrect signature verification in SimpleSAMLphpGHSA-2R3V-Q9X3-7G46Lowsimplesamlphp/simplesamlphp: Link injection in SimpleSAMLphpCVE-2020-5226Lowsimplesamlphp/simplesamlphp: Cross-site scripting in SimpleSAMLphpCVE-2020-5225Lowsimplesamlphp/simplesamlphp: Log injection in SimpleSAMLphp

Stop the waste.
Protect your environment with Kodem.