Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ping Identity — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting Ping Identity. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ping Identity operates as an enterprise identity and access management provider, specializing in single sign-on, multi-factor authentication, and API security for hybrid and cloud environments. Its software suite, which manages digital identities and permissions, has historically been associated with forty-eight recorded Common Vulnerabilities and Exposures. These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation or insecure direct object references within its web-based administrative interfaces. While the company has not been the subject of a widely publicized, large-scale data breach affecting millions of end-users, the high volume of CVEs indicates persistent challenges in securing its complex authentication infrastructure. These recurring issues highlight the risks inherent in deploying intricate identity governance tools, where misconfigurations or unpatched software components can potentially allow attackers to bypass authentication mechanisms or gain unauthorized administrative access to connected enterprise systems.

Found 18 results / 53 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-20773 Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint — PingFederate CWE-863 8.5 High 2026-09-14
CVE-2025-32736 PingFederate Administrative Console CSRF weaknesses — PingFederate CWE-352 4.9 Medium 2026-08-10
CVE-2025-26862 PingFederate unexpected browser flow initiation in redirectless mode — PingFederate CWE-307 9.8AI Critical AI 2025-10-27
CVE-2024-25573 Stored Cross-Site Scripting in Administrative Console Context — PingFederate CWE-79 5.4AI Medium AI 2025-06-15
CVE-2025-22854 Possible thread exhaustion from processing http responses in PingFederate Google Adapter — PingFederate CWE-394 7.5AI High AI 2025-06-15
CVE-2025-21085 PingFederate OAuth Grant attribute duplication may use excessive memory — PingFederate CWE-462 7.5AI High AI 2025-06-15
CVE-2024-21832 PingFederate REST API Data Store Injection — PingFederate CWE-94 3.5 Low 2024-07-09
CVE-2024-22377 PingFederate Runtime Node Path Traversal — PingFederate CWE-22 5.3 Medium 2024-07-09
CVE-2024-22477 PingFederate OIDC Policy Management Editor Cross-Site Scripting — PingFederate CWE-79 1.8 Low 2024-07-09
CVE-2023-40148 PingFederate Server Side Request Forgery vulnerability — PingFederate CWE-918 6.5 Medium 2024-04-10
CVE-2023-40545 PingFederate OAuth client_secret_jwt Authentication Bypass — PingFederate CWE-306 8.8 High 2024-02-06
CVE-2023-34085 User Attribute Disclosure via DynamoDB Data Stores — PingFederate CWE-359 2.6 Low 2023-10-25
CVE-2023-39219 Admin Console Denial of Service via Java class enumeration — PingFederate CWE-400 7.5 High 2023-10-25
CVE-2023-37283 Authentication Bypass via HTML Form & Identifier First Adapter — PingFederate CWE-287 8.1 High 2023-10-25
CVE-2022-40724 Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint. — PingFederate CWE-352 6.4 Medium 2023-04-25
CVE-2022-23722 PingFederate Password Reset via Authentication API Mishandling — PingFederate CWE-288 6.5 - 2022-05-02
CVE-2021-42000 Ping Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flows — PingFederate CWE-285 5.3 Medium 2022-02-10
CVE-2021-40329 Ping Identity PingFederate 加密问题漏洞 — PingFederate 9.8 - 2021-09-27

This page lists every published CVE security advisory associated with Ping Identity. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.