s
shibboleth
Security Risk Profile
47
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 11, 2011 to present
19
Total CVEs
10
Critical+High
0
Exploited
4
Unpatched
Threat Assessment
Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
47/100
medium
Severity Distribution
Critical
1High
9Medium
9Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
SSRF
2
2
Infoleak
2
3
SQL Injection
1
4
Null Pointer Dereference
1
5
Input Validation
1
Most Affected Products
1. Debian Debian Linux16
2. shibboleth Shibboleth-sp15
3. shibboleth OpenSAML14
4. shibboleth Shibboleth-identity-provider11
5. shibboleth Service Provider9
Recent Vulnerabilities
See more →CVE-2025-9943
CVSS 9.1EPSS 0%critical
Unauthenticated SQL Injection Vulnerability in Shibboleth Service Provider
Sep 10, 2025
CVE-2023-36661
CVSS 7.5high
Jun 25, 2023
CVE-2023-22947
CVSS 7.3high
Jan 11, 2023🔧 No Patch
CVE-2022-24129
CVSS 8.2high
Feb 4, 2022🔧 No Patch
CVE-2021-31826
CVSS 7.5high
Apr 26, 2021
CVE-2021-28963
CVSS 5.3medium
Mar 22, 2021
CVE-2020-27978
CVSS 7.5high
Oct 28, 2020🔧 No Patch
CVE-2019-19191
CVSS 7.8high
Nov 21, 2019🔧 No Patch
CVE-2010-2450
CVSS 7.5high
Nov 7, 2019
CVE-2018-0489
CVSS 6.5medium
Feb 27, 2018
Monitor shibboleth in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.