CVE-2023-6813Login by Auth0 <= 4.6.0 - Reflected Cross-Site Scripting via wleAuth0
CVE-2022-29172HTML injection with additional signup fieldsauth0 lock
CVE-2022-24794Open Redirect in express-openid-connectauth0 express-openid-connect
CVE-2022-23541jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA…auth0 node-jsonwebtoken
CVE-2022-23540jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()auth0 node-jsonwebtoken
CVE-2022-23539jsonwebtoken unrestricted key type could lead to legacy keys usageauth0 node-jsonwebtoken
CVE-2022-23505Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationauth0 passport-wsfed-saml2
CVE-2021-43812Open redirect in nextjs-auth0auth0 nextjs-auth0
CVE-2021-41246Session fixation in express-openid-connectauth0 express-openid-connect
CVE-2021-32702Reflected XSS from the callback handler's error query parameterauth0 nextjs-auth0
CVE-2021-32641Reflected XSS when using flashMessagesauth0 lock
CVE-2020-5263Information disclosure through error objectauth0 auth0.js
CVE-2020-15259CSRF in Auth0 ad-ldap-connectorauth0 ad-ldap-connector
CVE-2020-15240Regression in JWT Signature Validationauth0 omniauth-auth0
CVE-2020-15125Authorization header is not sanitized in an error object in auth0auth0 node-auth0