Flask-security-too
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Flask-security-too, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Flask-security-too CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High1
- Medium1
- Low1
Latest CVEs
The 6 most recently published vulnerabilities affecting Flask-security-too.
- CVE-2026-46715Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance—
- GHSA-f66q-9rf6-8795Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion—
- CVE-2023-49438An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter o...6.1
- CVE-2021-32618Open Redirect Vulnerability3.1
- GHSA-fxq4-r6mr-9x64CSRF Vuln can expose user's QRcode—
- CVE-2021-21241CSRF can expose users authentication token in Flask-Security-Too7.4
Product grouping is registry-driven, with AI assist and human review. How it works