Born05 maintains a focused two-factor authentication product portfolio, where the durable vulnerability signal centers on authentication-layer implementation weaknesses including improper authentication logic, algorithm errors, credential protection gaps, and sensitive-data serialization issues. These are structural concerns characteristic of systems handling user identity validation and cryptographic operations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Born05 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5657HIGH The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP. | Jun 6, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-5658MEDIUM The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. | Jun 6, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Born05.
Media articles that mention a CVE ID that affects a product developed by Born05 — matched by CVE ID, not by vendor name.