Xmlseclibs Project maintains a cryptographic XML-signing library that, despite narrow scope, embeds into applications requiring digital signature validation and is exposed wherever downstream systems process untrusted XML with cryptographic integrity checks. The vendor's observed vulnerability signal centers on improper validation of integrity check values, flawed cryptographic signature verification, and exception-handling gaps—weakness classes that strike at the core trust mechanisms the library is designed to enforce. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xmlseclibs Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3465HIGH Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an | Nov 7, 2019 | 8.8 | 29 | NO | NO |
CVE-2026-32313HIGH xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack | Mar 13, 2026 | 8.2 | 27 | NO | NO |
CVE-2025-66578HIGH xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 ca | Dec 9, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xmlseclibs Project.
Media articles that mention a CVE ID that affects a product developed by Xmlseclibs Project — matched by CVE ID, not by vendor name.