CVE-2015-2951: f21 Jwt

Medium severity, CVSS 5.0. EPSS: 3.7% chance of exploitation in the next 30 days.

JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.

Affected products

  • f21 Jwt: up to and including 1.0

Published 2015-06-05. Last modified 2026-06-17.