2fauth is a focused two-factor authentication application whose vulnerability profile centers on web-layer input handling and server-side request control, with recurring exposure in cross-site scripting variants, server-side request forgery, and race conditions in shared resource access. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2fauth over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32133CRITICAL 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability exists in 2FAuth that allows au | Mar 11, 2026 | 9.1 | 29 | NO | NO |
CVE-2025-45731MEDIUM A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other operations are pending. | Jul 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-52598HIGH 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF and URI v | Nov 20, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-52597MEDIUM 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior to 5.4.1 are vulnerable to stored cross-site scripting due | Nov 20, 2024 | 6.1 | 20 | NO | NO |
CVE-2023-36816MEDIUM 2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service fiel | Jul 3, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2fauth.
Media articles that mention a CVE ID that affects a product developed by 2fauth — matched by CVE ID, not by vendor name.