Zitadel

Vendor:

First CVE: Aug 31, 2022 · Active for 3 years

47
Total CVEs
More Total CVEs than 98% of tracked products
9.4
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Zitadel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2022
3 years ago
Most Recent CVE
May 14, 2026
75 days ago

CVE Severity & Scoring

Zitadel47 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network46 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low41 (87.2%)
High6 (12.8%)
Unknown0 (0.0%)
User Interaction
None34 (72.3%)
Unknown0 (0.0%)
Required13 (27.7%)
Privileges Required
Low11 (23.4%)
High5 (10.6%)
None31 (66.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process
Nov 13, 20259.834NONO
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account
Mar 7, 20269.333NONO
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADE
Mar 7, 20269.331NONO
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation,
May 14, 20267.530NONO
Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a
Oct 29, 20259.830NONO
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While
Oct 29, 20259.830NONO
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treat
Dec 9, 20258.629NONO
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilize
Oct 29, 20258.829NONO
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security p
Mar 7, 20268.228NONO
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference
Mar 4, 20259.028NONO

Exploit Exposure

Signals from CVEs in this product scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (47 CVEs).

Media Mentions

Signals from CVEs in this product scope (47 CVEs).

Top CNAs Publishing CVEs For Zitadel

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.018.80.3%00
3.0.018.00.4%00
2.62.036.80.4%00
2.61.036.80.4%00
2.58.025.70.6%00
2.57.025.70.6%00
2.55.016.50.6%00
2.46.026.70.6%00
2.45.026.80.6%00