Hybridauth Social Login Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    1
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2014-125116

    HybridAuth 2.0.9 - 2.2.2 Unauthenticated RCE via install.php Configuration Injection

    Last Modified: Apr 15, 2026
    Published: Jul 25, 2025

    CVE-2015-5511

    The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login.

    Last Modified: Apr 12, 2025
    Published: Aug 18, 2015

    CVE-2015-4395

    The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user for a password when registering" option is enabled, which allows remote authenticated users with certain permissions to obtain sensitive information by leveraging access to the database.

    Last Modified: Apr 12, 2025
    Published: Jun 15, 2015
    Items Per Page
    Hybridauth_Social_Login_Project Vulnerabilities & Security… | CVE-DB