The Two Factor Authentication Project maintains a narrowly focused authentication library whose modest CVE footprint belies its broad downstream distribution across identity-verification systems and access-control deployments. Treat this as a compact vendor profile reflecting the project's role as a foundational component rather than an end-user application; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Two Factor Authentication Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13279CRITICAL Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0. | Jan 9, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-13239CRITICAL Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0. | Jan 9, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-31694HIGH Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10. | Mar 31, 2025 | 8.1 | 21 | NO | NO |
CVE-2025-7030MEDIUM Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff | Jul 8, 2025 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Two Factor Authentication Project.
Media articles that mention a CVE ID that affects a product developed by Two Factor Authentication Project — matched by CVE ID, not by vendor name.