simplesamlphp has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 7.5 (high). Most affected products: simplesamlphp/saml2 (2), simplesamlphp/simplesamlphp (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- simplesamlphp/saml2 2
- simplesamlphp/simplesamlphp 1
Worst active — by depth score
CVE-2026-49283High· 8.7The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality48CVE-2026-49289High· 7.5The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality41CVE-2026-49284High· 7.1SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`39
simplesamlphp vulnerabilities
CVEs affecting simplesamlphp, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-49283High· 8.7The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically vali…
CVE-2026-49289High· 7.5The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath ev…
CVE-2026-49284High· 7.1SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`