Auth0 is a widely adopted identity and access management platform whose vulnerability profile reflects the centrality of authentication and session handling across modern web and mobile applications. The vendor's disclosure footprint spans authentication libraries such as auth0.js and nextjs-auth0, token-handling components like jsonwebtoken, and lock/login interfaces, products that sit in the critical path between applications and their users. Vulnerabilities affecting Auth0 skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including cross-site scripting, improper authentication, CSRF, authorization flaws, and cryptographic signature verification issues—classes that are characteristic of identity platforms where a single flaw can compromise authentication or session integrity across dependent applications. Defenders should treat Auth0 advisories as broadly applicable across their application portfolios and prioritize updates to authentication libraries and login flows; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Auth0 over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9235CRITICAL In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but | May 29, 2018 | 9.8 | 33 | NO | NO |
CVE-2026-34236CRITICAL Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypte | Apr 1, 2026 | 9.8 | 32 | NO | NO |
CVE-2018-6873CRITICAL The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated. | Apr 4, 2018 | 9.8 | 31 | NO | NO |
CVE-2020-7947CRITICAL An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with | Apr 1, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-7644CRITICAL Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is prese | Apr 11, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-15084CRITICAL In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in th | Jun 30, 2020 | 9.1 | 29 | NO | NO |
CVE-2022-23539HIGH Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with | Dec 23, 2022 | 8.1 | 27 | NO | NO |
CVE-2021-41246HIGH Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session | Dec 9, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-5391HIGH Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field. | Apr 1, 2020 | 8.8 | 27 | NO | NO |
CVE-2018-15121HIGH An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. Thi | Aug 29, 2018 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Auth0.
Media articles that mention a CVE ID that affects a product developed by Auth0 — matched by CVE ID, not by vendor name.