Technology · Packagist
simplesamlphp/simplesamlphp (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 23 vulnerabilities in simplesamlphp/simplesamlphp (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, SimpleSAMLphp Information Disclosure vulnerability, was published on 28 May 2024.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About simplesamlphp/simplesamlphp (Packagist)
An open-source PHP authentication and federation application that supports SAML 2.0.
Latest simplesamlphp/simplesamlphp (Packagist) vulnerabilities
- SimpleSAMLphp Information Disclosure vulnerabilitylowCVSS 3.1
- SimpleSAMLphp Reflected Cross-site Scripting vulnerabilitylowCVSS 3.1
- Duplicate Advisory: SimpleSAMLphp signature validation bypassinfo
- SimpleSAMLphp exposes credentials in session storagelowCVSS 3.1
- SimpleSAMLphp Link Injection vulnerabilitylowCVSS 3.1
- CVE-2017-12870: SimpleSAMLphp Unauthenticated encryption in CBC modelowCVSS 3EPSS 0.9%
- CVE-2017-12871: SimpleSAMLphp Incorrect IV generation for encryptionlowCVSS 3EPSS 0.5%
- CVE-2018-6520: SimpleSAMLphp Open redirection protection bypasslowCVSS 3EPSS 0.9%
- CVE-2017-12868: SimpleSAMLphp Session fixation issue and authentication bypass in the authcrypt modulelowCVSS 3EPSS 2.1%
- CVE-2016-3124: SimpleSAMLphp Information leakage issue in the sanitycheck modulelowCVSS 3EPSS 1.3%
- CVE-2017-12869: SimpleSAMLphp Authentication context bypass in the multiauth modulelowCVSS 3EPSS 2.4%
- CVE-2017-18121: SimpleSAMLphp XSS VulnerabilitylowCVSS 3EPSS 1.2%
- CVE-2017-18122: SimpleSAMLphp Signature validation bypasslowCVSS 3EPSS 1.1%
- CVE-2017-12872: SimpleSAMLphp allows timing side-channel attackslowCVSS 3EPSS 1.5%
- CVE-2018-6521: SimpleSAMLphp Use of insecure connection charset (sqlauth module)lowCVSS 3EPSS 3.0%
- CVE-2017-12867: SimpleSAMLphp Invalid token creation and validationlowCVSS 3EPSS 1.3%
- CVE-2011-4625: simpleSAMLphp incorrectly handles XML encryptionlowCVSS 3.1EPSS 0.7%
- CVE-2020-5301: Information disclosure of source code in SimpleSAMLphplowCVSS 3.1EPSS 0.9%
- CVE-2017-12873: Incorrect persistent NameID generation in SimpleSAMLphplowCVSS 3EPSS 1.7%
- CVE-2016-9955: Incorrect signature verification in SimpleSAMLphplowCVSS 3EPSS 1.2%
- Link injection in SimpleSAMLphplowCVSS 3.1
- CVE-2020-5226: Cross-site scripting in SimpleSAMLphplowCVSS 3.1EPSS 0.5%
- CVE-2020-5225: Log injection in SimpleSAMLphplowCVSS 3.1EPSS 0.7%
Most severe simplesamlphp/simplesamlphp (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-5301: Information disclosure of source code in SimpleSAMLphplowCVSS 3.1EPSS 0.9%
- CVE-2011-4625: simpleSAMLphp incorrectly handles XML encryptionlowCVSS 3.1EPSS 0.7%
- CVE-2020-5225: Log injection in SimpleSAMLphplowCVSS 3.1EPSS 0.7%
- CVE-2020-5226: Cross-site scripting in SimpleSAMLphplowCVSS 3.1EPSS 0.5%
- SimpleSAMLphp Information Disclosure vulnerabilitylowCVSS 3.1
- SimpleSAMLphp Reflected Cross-site Scripting vulnerabilitylowCVSS 3.1
- SimpleSAMLphp exposes credentials in session storagelowCVSS 3.1
- SimpleSAMLphp Link Injection vulnerabilitylowCVSS 3.1
- Link injection in SimpleSAMLphplowCVSS 3.1
- CVE-2018-6521: SimpleSAMLphp Use of insecure connection charset (sqlauth module)lowCVSS 3EPSS 3.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/simplesamlphp-simplesamlphp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "simplesamlphp/simplesamlphp (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/simplesamlphp-simplesamlphp, 27 September 2026.