Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Auth0

First CVE: Dec 6, 2017Active for: 9 yearsTotal CVEs: 42
28.0
VTI Score
Low

Auth0 is a widely adopted identity and access management platform whose vulnerability profile reflects the centrality of authentication and session handling across modern web and mobile applications. The vendor's disclosure footprint spans authentication libraries such as auth0.js and nextjs-auth0, token-handling components like jsonwebtoken, and lock/login interfaces, products that sit in the critical path between applications and their users. Vulnerabilities affecting Auth0 skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including cross-site scripting, improper authentication, CSRF, authorization flaws, and cryptographic signature verification issues—classes that are characteristic of identity platforms where a single flaw can compromise authentication or session integrity across dependent applications. Defenders should treat Auth0 advisories as broadly applicable across their application portfolios and prioritize updates to authentication libraries and login flows; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Auth0 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2017
8 years ago
Most Recent CVE
May 27, 2026
58 days ago

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-9235CRITICAL
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but
May 29, 20189.833NONO
CVE-2026-34236CRITICAL
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypte
Apr 1, 20269.832NONO
CVE-2018-6873CRITICAL
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
Apr 4, 20189.831NONO
CVE-2020-7947CRITICAL
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with
Apr 1, 20209.830NONO
CVE-2019-7644CRITICAL
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is prese
Apr 11, 20199.830NONO
CVE-2020-15084CRITICAL
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in th
Jun 30, 20209.129NONO
CVE-2022-23539HIGH
Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with
Dec 23, 20228.127NONO
CVE-2021-41246HIGH
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session
Dec 9, 20218.827NONO
CVE-2020-5391HIGH
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
Apr 1, 20208.827NONO
CVE-2018-15121HIGH
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. Thi
Aug 29, 20188.827NONO
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
40%
43%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network42 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (90.5%)
High4 (9.5%)
Unknown0 (0.0%)
User Interaction
None21 (50.0%)
Unknown0 (0.0%)
Required21 (50.0%)
Privileges Required
Low9 (21.4%)
High2 (4.8%)
None31 (73.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Auth0.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Auth0 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Auth0's Products

View all 4 CNAs →

Top CWEs