{"schema_version":1,"title":"simplesamlphp/simplesamlphp (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in simplesamlphp/simplesamlphp (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, SimpleSAMLphp Information Disclosure vulnerability, was published on 28 May 2024.","url":"https://junglewise.ai/threats/technologies/simplesamlphp-simplesamlphp","json_url":"https://junglewise.ai/threats/technologies/simplesamlphp-simplesamlphp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/simplesamlphp-simplesamlphp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":23,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cvss":3.1,"slug":"simplesamlphp-information-disclosure-vulnerability-07de5cdd","title":"SimpleSAMLphp Information Disclosure vulnerability","severity":"low","exploited":false,"published_at":"2024-05-28T21:26:21+00:00","url":"https://junglewise.ai/threats/simplesamlphp-information-disclosure-vulnerability-07de5cdd"},{"cvss":3.1,"slug":"simplesamlphp-reflected-cross-site-scripting-vulnerability-76196f28","title":"SimpleSAMLphp Reflected Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2024-05-28T20:55:51+00:00","url":"https://junglewise.ai/threats/simplesamlphp-reflected-cross-site-scripting-vulnerability-76196f28"},{"slug":"duplicate-advisory-simplesamlphp-signature-validation-bypass-85859e99","title":"Duplicate Advisory: SimpleSAMLphp signature validation bypass","severity":"info","exploited":false,"published_at":"2024-05-28T19:29:37+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-simplesamlphp-signature-validation-bypass-85859e99"},{"cvss":3.1,"slug":"simplesamlphp-exposes-credentials-in-session-storage-0757537a","title":"SimpleSAMLphp exposes credentials in session storage","severity":"low","exploited":false,"published_at":"2024-05-28T18:28:53+00:00","url":"https://junglewise.ai/threats/simplesamlphp-exposes-credentials-in-session-storage-0757537a"},{"cvss":3.1,"slug":"simplesamlphp-link-injection-vulnerability-fff04b79","title":"SimpleSAMLphp Link Injection vulnerability","severity":"low","exploited":false,"published_at":"2024-05-28T18:26:35+00:00","url":"https://junglewise.ai/threats/simplesamlphp-link-injection-vulnerability-fff04b79"},{"cve":"CVE-2017-12870","cvss":3,"epss":0.0088,"slug":"cve-2017-12870-simplesamlphp-unauthenticated-encryption-in-cbc-mode","title":"SimpleSAMLphp Unauthenticated encryption in CBC mode","severity":"low","exploited":false,"published_at":"2022-05-17T01:17:12+00:00","url":"https://junglewise.ai/threats/cve-2017-12870-simplesamlphp-unauthenticated-encryption-in-cbc-mode"},{"cve":"CVE-2017-12871","cvss":3,"epss":0.0049,"slug":"cve-2017-12871-simplesamlphp-incorrect-iv-generation-for-encryption","title":"SimpleSAMLphp Incorrect IV generation for encryption","severity":"low","exploited":false,"published_at":"2022-05-17T01:17:12+00:00","url":"https://junglewise.ai/threats/cve-2017-12871-simplesamlphp-incorrect-iv-generation-for-encryption"},{"cve":"CVE-2018-6520","cvss":3,"epss":0.0085,"slug":"cve-2018-6520-simplesamlphp-open-redirection-protection-bypass","title":"SimpleSAMLphp Open redirection protection bypass","severity":"low","exploited":false,"published_at":"2022-05-14T03:44:35+00:00","url":"https://junglewise.ai/threats/cve-2018-6520-simplesamlphp-open-redirection-protection-bypass"},{"cve":"CVE-2017-12868","cvss":3,"epss":0.0213,"slug":"cve-2017-12868-simplesamlphp-session-fixation-issue-and-authentication-bypass-in","title":"SimpleSAMLphp Session fixation issue and authentication bypass in the authcrypt module","severity":"low","exploited":false,"published_at":"2022-05-14T03:15:07+00:00","url":"https://junglewise.ai/threats/cve-2017-12868-simplesamlphp-session-fixation-issue-and-authentication-bypass-in"},{"cve":"CVE-2016-3124","cvss":3,"epss":0.0134,"slug":"cve-2016-3124-simplesamlphp-information-leakage-issue-in-the-sanitycheck-module","title":"SimpleSAMLphp Information leakage issue in the sanitycheck module","severity":"low","exploited":false,"published_at":"2022-05-14T02:57:54+00:00","url":"https://junglewise.ai/threats/cve-2016-3124-simplesamlphp-information-leakage-issue-in-the-sanitycheck-module"},{"cve":"CVE-2017-12869","cvss":3,"epss":0.0237,"slug":"cve-2017-12869-simplesamlphp-authentication-context-bypass-in-the-multiauth","title":"SimpleSAMLphp Authentication context bypass in the multiauth module","severity":"low","exploited":false,"published_at":"2022-05-14T01:04:19+00:00","url":"https://junglewise.ai/threats/cve-2017-12869-simplesamlphp-authentication-context-bypass-in-the-multiauth"},{"cve":"CVE-2017-18121","cvss":3,"epss":0.012,"slug":"cve-2017-18121-simplesamlphp-xss-vulnerability","title":"SimpleSAMLphp XSS Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T01:04:10+00:00","url":"https://junglewise.ai/threats/cve-2017-18121-simplesamlphp-xss-vulnerability"},{"cve":"CVE-2017-18122","cvss":3,"epss":0.0109,"slug":"cve-2017-18122-simplesamlphp-signature-validation-bypass","title":"SimpleSAMLphp Signature validation bypass","severity":"low","exploited":false,"published_at":"2022-05-14T01:04:08+00:00","url":"https://junglewise.ai/threats/cve-2017-18122-simplesamlphp-signature-validation-bypass"},{"cve":"CVE-2017-12872","cvss":3,"epss":0.0146,"slug":"cve-2017-12872-simplesamlphp-allows-timing-side-channel-attacks","title":"SimpleSAMLphp allows timing side-channel attacks","severity":"low","exploited":false,"published_at":"2022-05-14T01:04:04+00:00","url":"https://junglewise.ai/threats/cve-2017-12872-simplesamlphp-allows-timing-side-channel-attacks"},{"cve":"CVE-2018-6521","cvss":3,"epss":0.0305,"slug":"cve-2018-6521-simplesamlphp-use-of-insecure-connection-charset-sqlauth-module","title":"SimpleSAMLphp Use of insecure connection charset (sqlauth module)","severity":"low","exploited":false,"published_at":"2022-05-13T01:53:07+00:00","url":"https://junglewise.ai/threats/cve-2018-6521-simplesamlphp-use-of-insecure-connection-charset-sqlauth-module"},{"cve":"CVE-2017-12867","cvss":3,"epss":0.0125,"slug":"cve-2017-12867-simplesamlphp-invalid-token-creation-and-validation","title":"SimpleSAMLphp Invalid token creation and validation","severity":"low","exploited":false,"published_at":"2022-05-13T01:42:46+00:00","url":"https://junglewise.ai/threats/cve-2017-12867-simplesamlphp-invalid-token-creation-and-validation"},{"cve":"CVE-2011-4625","cvss":3.1,"epss":0.0074,"slug":"cve-2011-4625-simplesamlphp-incorrectly-handles-xml-encryption","title":"simpleSAMLphp incorrectly handles XML encryption","severity":"low","exploited":false,"published_at":"2022-04-22T00:24:09+00:00","url":"https://junglewise.ai/threats/cve-2011-4625-simplesamlphp-incorrectly-handles-xml-encryption"},{"cve":"CVE-2020-5301","cvss":3.1,"epss":0.0092,"slug":"cve-2020-5301-information-disclosure-of-source-code-in-simplesamlphp","title":"Information disclosure of source code in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-04-22T20:59:44+00:00","url":"https://junglewise.ai/threats/cve-2020-5301-information-disclosure-of-source-code-in-simplesamlphp"},{"cve":"CVE-2017-12873","cvss":3,"epss":0.0166,"slug":"cve-2017-12873-incorrect-persistent-nameid-generation-in-simplesamlphp","title":"Incorrect persistent NameID generation in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:28:06+00:00","url":"https://junglewise.ai/threats/cve-2017-12873-incorrect-persistent-nameid-generation-in-simplesamlphp"},{"cve":"CVE-2016-9955","cvss":3,"epss":0.0118,"slug":"cve-2016-9955-incorrect-signature-verification-in-simplesamlphp","title":"Incorrect signature verification in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:27:42+00:00","url":"https://junglewise.ai/threats/cve-2016-9955-incorrect-signature-verification-in-simplesamlphp"},{"cvss":3.1,"slug":"link-injection-in-simplesamlphp-790b72de","title":"Link injection in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:27:16+00:00","url":"https://junglewise.ai/threats/link-injection-in-simplesamlphp-790b72de"},{"cve":"CVE-2020-5226","cvss":3.1,"epss":0.0054,"slug":"cve-2020-5226-cross-site-scripting-in-simplesamlphp","title":"Cross-site scripting in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:26:54+00:00","url":"https://junglewise.ai/threats/cve-2020-5226-cross-site-scripting-in-simplesamlphp"},{"cve":"CVE-2020-5225","cvss":3.1,"epss":0.0066,"slug":"cve-2020-5225-log-injection-in-simplesamlphp","title":"Log injection in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:26:13+00:00","url":"https://junglewise.ai/threats/cve-2020-5225-log-injection-in-simplesamlphp"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"simplesamlphp/simplesamlphp (Packagist)","slug":"simplesamlphp-simplesamlphp","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://simplesamlphp.org/","repo_url":"https://github.com/simplesamlphp/simplesamlphp","description":"An open-source PHP authentication and federation application that supports SAML 2.0.","url":"https://junglewise.ai/threats/technologies/simplesamlphp-simplesamlphp"},"most_severe":[{"cve":"CVE-2020-5301","cvss":3.1,"epss":0.0092,"slug":"cve-2020-5301-information-disclosure-of-source-code-in-simplesamlphp","title":"Information disclosure of source code in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-04-22T20:59:44+00:00","url":"https://junglewise.ai/threats/cve-2020-5301-information-disclosure-of-source-code-in-simplesamlphp"},{"cve":"CVE-2011-4625","cvss":3.1,"epss":0.0074,"slug":"cve-2011-4625-simplesamlphp-incorrectly-handles-xml-encryption","title":"simpleSAMLphp incorrectly handles XML encryption","severity":"low","exploited":false,"published_at":"2022-04-22T00:24:09+00:00","url":"https://junglewise.ai/threats/cve-2011-4625-simplesamlphp-incorrectly-handles-xml-encryption"},{"cve":"CVE-2020-5225","cvss":3.1,"epss":0.0066,"slug":"cve-2020-5225-log-injection-in-simplesamlphp","title":"Log injection in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:26:13+00:00","url":"https://junglewise.ai/threats/cve-2020-5225-log-injection-in-simplesamlphp"},{"cve":"CVE-2020-5226","cvss":3.1,"epss":0.0054,"slug":"cve-2020-5226-cross-site-scripting-in-simplesamlphp","title":"Cross-site scripting in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:26:54+00:00","url":"https://junglewise.ai/threats/cve-2020-5226-cross-site-scripting-in-simplesamlphp"},{"cvss":3.1,"slug":"simplesamlphp-information-disclosure-vulnerability-07de5cdd","title":"SimpleSAMLphp Information Disclosure vulnerability","severity":"low","exploited":false,"published_at":"2024-05-28T21:26:21+00:00","url":"https://junglewise.ai/threats/simplesamlphp-information-disclosure-vulnerability-07de5cdd"},{"cvss":3.1,"slug":"simplesamlphp-reflected-cross-site-scripting-vulnerability-76196f28","title":"SimpleSAMLphp Reflected Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2024-05-28T20:55:51+00:00","url":"https://junglewise.ai/threats/simplesamlphp-reflected-cross-site-scripting-vulnerability-76196f28"},{"cvss":3.1,"slug":"simplesamlphp-exposes-credentials-in-session-storage-0757537a","title":"SimpleSAMLphp exposes credentials in session storage","severity":"low","exploited":false,"published_at":"2024-05-28T18:28:53+00:00","url":"https://junglewise.ai/threats/simplesamlphp-exposes-credentials-in-session-storage-0757537a"},{"cvss":3.1,"slug":"simplesamlphp-link-injection-vulnerability-fff04b79","title":"SimpleSAMLphp Link Injection vulnerability","severity":"low","exploited":false,"published_at":"2024-05-28T18:26:35+00:00","url":"https://junglewise.ai/threats/simplesamlphp-link-injection-vulnerability-fff04b79"},{"cvss":3.1,"slug":"link-injection-in-simplesamlphp-790b72de","title":"Link injection in SimpleSAMLphp","severity":"low","exploited":false,"published_at":"2020-01-24T21:27:16+00:00","url":"https://junglewise.ai/threats/link-injection-in-simplesamlphp-790b72de"},{"cve":"CVE-2018-6521","cvss":3,"epss":0.0305,"slug":"cve-2018-6521-simplesamlphp-use-of-insecure-connection-charset-sqlauth-module","title":"SimpleSAMLphp Use of insecure connection charset (sqlauth module)","severity":"low","exploited":false,"published_at":"2022-05-13T01:53:07+00:00","url":"https://junglewise.ai/threats/cve-2018-6521-simplesamlphp-use-of-insecure-connection-charset-sqlauth-module"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}