simplesamlphp
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 34 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 24, 2012 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding
Validation of SignedInfo
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
simplesamlphp simplesamlphp-module-openidprovider trust.tpl.php cross site scripting
Information Cards Module cross site scripting
SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scripting
Cross-site scripting in SimpleSAMLphp
Monitor simplesamlphp in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.