Pingfederate

Vendor:

First CVE: Dec 12, 2014 · Active for 11 years

20
Total CVEs
More Total CVEs than 94% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pingfederate over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2014
11 years ago
Most Recent CVE
Oct 27, 2025
270 days ago

CVE Severity & Scoring

Pingfederate20 CVEs
All CVEs352,294 CVEs
LowMediumHighCriticalNone
Attack Vector
Local0 (0.0%)
Network18 (90.0%)
Unknown1 (5.0%)
Physical0 (0.0%)
Adjacent Network1 (5.0%)
Attack Complexity
Low15 (75.0%)
High4 (20.0%)
Unknown1 (5.0%)
User Interaction
None13 (65.0%)
Unknown1 (5.0%)
Required2 (10.0%)
Privileges Required
Low8 (40.0%)
High3 (15.0%)
None8 (40.0%)
Unknown1 (5.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
Sep 27, 20219.830NONO
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
Feb 6, 20249.827NONO
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
Apr 25, 20238.827NONO
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
Oct 25, 20239.825NONO
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
Oct 7, 20217.524NONO
Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct p
Dec 12, 20146.424NONO
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an e
Feb 10, 20226.522NONO
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
Apr 25, 20236.521NONO
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
Oct 25, 20237.520NONO
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictiona
Apr 25, 20235.820NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Pingfederate

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3.326.50.5%00
6.10.116.42.9%00
12.0.024.80.3%00
11.3.039.00.8%00
11.0.016.50.6%00