FusionAuth provides an identity and access-management platform centered on authentication and SAML v2 federation, with the durable signal reflecting application-layer input-handling and validation weaknesses including path traversal, expression language injection, XML external entity processing, and cryptographic signature verification. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fusionauth over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7799HIGH An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Th | Jan 28, 2020 | 7.2 | 28 | NO | NO |
CVE-2022-45921HIGH FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve | Nov 28, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-12676CRITICAL FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusi | Oct 2, 2020 | 9.1 | 23 | NO | NO |
CVE-2021-27736MEDIUM FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafel | Apr 22, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fusionauth.
Media articles that mention a CVE ID that affects a product developed by Fusionauth — matched by CVE ID, not by vendor name.