Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Onelogin

First CVE: Jan 23, 2017Active for: 9 yearsTotal CVEs: 11
66.4
VTI Score
TOP TARGET

Onelogin maintains a focused portfolio of SAML authentication and single sign-on libraries and services that sit at the identity layer of many enterprise integrations, and these products skew strongly toward critical-severity outcomes. The vendor's recurring vulnerabilities center on cryptographic signature verification, authentication logic, and command injection risks that are endemic to identity-federation parsers and protocol handlers, and public exploit code has a regular presence in the ecosystem surrounding these flaws. Defenders should prioritize Onelogin authentication components in supply-chain inventories and treat advisories for its SAML implementations as high-priority; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
9.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Onelogin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Dec 9, 2025
228 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-25292CRITICAL
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a
Mar 12, 20259.867NONO
CVE-2025-25291CRITICAL
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a
Mar 12, 20259.853NOYES
CVE-2024-45409CRITICAL
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Resp
Sep 10, 20249.852NOYES
CVE-2025-66568CRITICAL
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonica
Dec 9, 20259.131NONO
CVE-2025-66567CRITICAL
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due
Dec 9, 20259.131NONO
CVE-2017-11427CRITICAL
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate th
Apr 17, 20199.831NONO
CVE-2015-20108CRITICAL
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
May 27, 20239.830NONO
CVE-2017-11428CRITICAL
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the
Apr 17, 20199.825NONO
CVE-2025-25293HIGH
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Servic
Mar 12, 20257.523NONO
CVE-2016-10928HIGH
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
Aug 22, 20197.519NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
73%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
18.2% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Onelogin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Onelogin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Onelogin's Products

View all 3 CNAs →

Top CWEs