The One Time Password Project maintains a focused authentication library with a narrow product scope but broad reliance as an underlying component in identity-management systems across multiple vendors' platforms. Its vulnerability footprint centers on the authentication-bypass mechanism itself, with recurring weaknesses in alternate authentication paths and capture-replay vulnerabilities that reflect the inherent challenges of time-based or challenge-response credential schemes. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by One Time Password Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48012MEDIUM Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 be | May 21, 2025 | 4.8 | 15 | NO | NO |
CVE-2025-48011MEDIUM Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 befo | May 21, 2025 | 4.8 | 15 | NO | NO |
CVE-2025-48010MEDIUM Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 befo | May 21, 2025 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by One Time Password Project.
Media articles that mention a CVE ID that affects a product developed by One Time Password Project — matched by CVE ID, not by vendor name.