Email Tfa Project maintains a narrowly scoped two-factor authentication product whose vulnerability footprint centers on authentication mechanisms, with recurring issues around alternate authentication paths, brute-force resistance, and credential validation. The durable profile reflects the authentication-critical role this category of software plays; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Email Tfa Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31676HIGH Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3. | Mar 31, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-12760MEDIUM Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6. | Nov 18, 2025 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Email Tfa Project.
Media articles that mention a CVE ID that affects a product developed by Email Tfa Project — matched by CVE ID, not by vendor name.