VDB
Sign up

package

Packagist/simplesamlphp/simplesamlphp

pkg:packagist/simplesamlphp/simplesamlphp

MEDIUM5.3Packagist
GHSA-7wh8-jrq7-p27f

SimpleSAMLphp exposes credentials in session storage

Modified: 12/3/2024

MEDIUM5.9Packagist
GHSA-ppm4-r2vc-pg74

SimpleSAMLphp Information Disclosure vulnerability

Modified: 12/3/2024

HIGH7.1Packagist
GHSA-q8r6-xj3f-wrrm· CVE-2026-49284

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`

Modified: 9/10/2026

MEDIUM5.4Packagist
GHSA-v858-922f-fj9v

SimpleSAMLphp Link Injection vulnerability

Modified: 12/3/2024

MEDIUM6.1Packagist
GHSA-vpr3-cw3h-prw8

SimpleSAMLphp Reflected Cross-site Scripting vulnerability

Modified: 12/3/2024