Onelogin maintains a focused portfolio of SAML authentication and single sign-on libraries and services that sit at the identity layer of many enterprise integrations, and these products skew strongly toward critical-severity outcomes. The vendor's recurring vulnerabilities center on cryptographic signature verification, authentication logic, and command injection risks that are endemic to identity-federation parsers and protocol handlers, and public exploit code has a regular presence in the ecosystem surrounding these flaws. Defenders should prioritize Onelogin authentication components in supply-chain inventories and treat advisories for its SAML implementations as high-priority; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onelogin over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25292CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 67 | NO | NO |
CVE-2025-25291CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 53 | NO | YES |
CVE-2024-45409CRITICAL The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Resp | Sep 10, 2024 | 9.8 | 52 | NO | YES |
CVE-2025-66568CRITICAL The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonica | Dec 9, 2025 | 9.1 | 31 | NO | NO |
CVE-2025-66567CRITICAL The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due | Dec 9, 2025 | 9.1 | 31 | NO | NO |
CVE-2017-11427CRITICAL OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate th | Apr 17, 2019 | 9.8 | 31 | NO | NO |
CVE-2015-20108CRITICAL xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. | May 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-11428CRITICAL OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the | Apr 17, 2019 | 9.8 | 25 | NO | NO |
CVE-2025-25293HIGH ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Servic | Mar 12, 2025 | 7.5 | 23 | NO | NO |
CVE-2016-10928HIGH The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users. | Aug 22, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onelogin.
Media articles that mention a CVE ID that affects a product developed by Onelogin — matched by CVE ID, not by vendor name.