Filtered by vendor Drupal Subscriptions
Filtered by product Openid Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-12466 1 Drupal 2 Drupal, Openid 2025-10-30 7.5 High
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7.
CVE-2008-0570 1 Drupal 1 Openid 2025-04-09 N/A
The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.