📦 Two Factor Authentication

by Two Factor Authentication Project

🔍 What is Two Factor Authentication?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-13279

CRITICAL CVSS 9.8 Jan 9, 2025

A session fixation vulnerability in Drupal's Two-factor Authentication (TFA) module allows attackers to hijack user sessions by fixing session IDs before authentication. This affects all Drupal sites ...

CVE-2024-13239

CRITICAL CVSS 9.8 Jan 9, 2025

A weak authentication vulnerability in Drupal's Two-factor Authentication (TFA) module allows attackers to bypass 2FA protections and gain unauthorized access. This affects all Drupal sites using the ...

CVE-2025-31694

HIGH CVSS 8.1 Mar 31, 2025

This vulnerability in Drupal's Two-factor Authentication (TFA) module allows attackers to bypass 2FA through forceful browsing techniques. It affects all Drupal sites using TFA module versions before ...