Shibboleth

    Dashboard / Vendors

    Products: 10
    Vulnerabilities: 20
    Known Exploited: 0
    1
    Critical Level Threats
    10
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-12281

    Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing

    Last Modified: Aug 05, 2026
    Published: Jul 15, 2026

    CVE-2025-9943

    Unauthenticated SQL Injection Vulnerability in Shibboleth Service Provider

    Last Modified: Apr 15, 2026
    Published: Sep 10, 2025

    CVE-2023-36661

    XMLTooling: SSRF via a crafted KeyInfo element

    Last Modified: May 05, 2025
    Published: Jun 25, 2023

    CVE-2023-22947

    Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

    Last Modified: Apr 07, 2025
    Published: Jan 11, 2023

    CVE-2022-24129

    The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

    Last Modified: Nov 21, 2024
    Published: Feb 04, 2022
    Items Per Page
    Shibboleth Vulnerabilities & Security CVEs | CVE-DB