CWE-90 · 85 records
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVEs in this class
86 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2016-9299Weaponized | The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized jenkins · jenkins · CWE-90 | Critical9.8 | — | 96.9% | Jan 12, 2017 |
41Plan | CVE-2017-14596No exploit | In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.joomla · joomla\! · CWE-90 | Critical9.8 | — | 6.9% | Sep 20, 2017 |
40Plan | CVE-2021-43350No exploit | LDAP filter injection vulnerability in Traffic Opsapache · traffic control · CWE-90 | Critical9.8 | — | 4.8% | Nov 11, 2021 |
39Monitor | CVE-2023-29050No exploit | The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outsideopen-xchange · ox app suite · CWE-90 | Critical9.6 | — | 1.7% | Jan 8, 2024 |
39Monitor | CVE-2011-4069No exploit | html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authenticpacketfence · packetfence · CWE-90 | Critical9.8 | — | 1.6% | Feb 1, 2018 |
39Monitor | CVE-2017-8790No exploit | An issue was discovered on Accellion FTA devices before FTA_9_12_180.accellion · file transfer appliance · CWE-90 | Critical9.8 | — | 1.4% | May 5, 2017 |
39Monitor | CVE-2024-33868No exploit | An issue was discovered in linqi before 1.4.0.1 on Windows.linqi · linqi · CWE-90 | Critical9.8 | — | 0.9% | May 14, 2024 |
39Monitor | CVE-2015-10027No exploit | hydrian TTRSS-Auth-LDAP Username ldap injectionttrrs-auth-ldap project · ttrrs-auth-ldap · CWE-90 | Critical9.8 | — | 0.8% | Jan 7, 2023 |
39Monitor | CVE-2026-33289No exploit | SuiterCRM has LDAP Filter Injection in Authentication Modulesuitecrm · suitecrm · CWE-90 | Critical9.8 | — | 0.8% | Mar 19, 2026 |
39Monitor | CVE-2024-54852No exploit | When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectiosismics · teedy · CWE-90 | Critical9.8 | — | 0.8% | Jan 29, 2025 |
39Monitor | CVE-2023-6905No exploit | Jahastech NxFilter Bind Request ldap injectionnxfilter · nxfilter · CWE-90 | Critical9.8 | — | 0.7% | Dec 17, 2023 |
39Monitor | CVE-2026-44930No exploit | Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repositoryapache · cxf · CWE-90 | Critical9.8 | — | 0.5% | May 22, 2026 |
37Monitor | CVE-2026-46619No exploit | OpenAM Authentication Bypass via MSISDN LDAP Injectionopenidentityplatform · openam · CWE-90 | Critical9.3 | — | 1.0% | Sep 15, 2026 |
36Monitor | CVE-2026-41919No exploit | Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Constructionapache · ofbiz · CWE-90 | Critical9.1 | — | 0.6% | May 19, 2026 |
36Monitor | CVE-2024-56841No exploit | A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).siemens · mendix ldap · CWE-90 | Critical9.1 | — | 0.5% | Jan 14, 2025 |
36Monitor | CVE-2026-94053No exploit | Apache MINA SSHD: LDAP injection in sshd-ldapapache software foundation · apache mina sshd · CWE-90 | Critical9.1 | — | — | Today |
35Monitor | CVE-2022-4254No exploit | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filtersfedoraproject · sssd · CWE-90 | High8.8 | — | 1.0% | Feb 1, 2023 |
35Monitor | CVE-2026-47303No exploit | ASP.NET Core Elevation of Privilege Vulnerabilitymicrosoft · .net · CWE-90 | High8.8 | — | 0.8% | Jul 14, 2026 |
35Monitor | CVE-2026-58222No exploit | Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributesred hat · red hat enterprise linux 10 · CWE-90 | High8.8 | — | 0.8% | Jul 30, 2026 |
35Monitor | CVE-2026-49268Proof of concept | Apache Shiro: LDAP DN Injection in DefaultLdapRealmapache · shiro · CWE-90 | High8.8 | — | 0.8% | Jun 17, 2026 |
35Monitor | CVE-2026-39962No exploit | LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variablemisp-project · misp · CWE-90 | High8.8 | — | 0.7% | Apr 9, 2026 |
35Monitor | CVE-2025-48208No exploit | Apache HertzBeat (incubating): Jmx JNDI injection vulnerabilityapache · hertzbeat · CWE-90 | High8.8 | — | 0.6% | Sep 9, 2025 |
35Monitor | CVE-2026-13696No exploit | LDAP Injection in HAVELSAN's Liman MYShavelsan inc. · liman mys · CWE-90 | High8.8 | — | 0.5% | Jul 7, 2026 |
34Monitor | CVE-2026-25560No exploit | WeKan < 8.19 LDAP Authentication Filter Injectionwekan project · wekan · CWE-90 | High8.7 | — | 0.9% | Feb 7, 2026 |
34Monitor | CVE-2026-40459No exploit | LDAP Injection in PAC4Jpac4j · pac4j · CWE-90 | High8.7 | — | 0.7% | Apr 17, 2026 |
- CVE-2016-929968This week
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized
CriticalCVSS 9.8WeaponizedEPSS 97%jenkins · jenkinsJan 12, 2017
- CVE-2017-1459641Plan
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
CriticalCVSS 9.8No exploitEPSS 7%joomla · joomla\!Sep 20, 2017
- CVE-2021-4335040Plan
LDAP filter injection vulnerability in Traffic Ops
CriticalCVSS 9.8No exploitEPSS 5%apache · traffic controlNov 11, 2021
- CVE-2023-2905039Monitor
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside
CriticalCVSS 9.6No exploitEPSS 2%open-xchange · ox app suiteJan 8, 2024
- CVE-2011-406939Monitor
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentic
CriticalCVSS 9.8No exploitEPSS 2%packetfence · packetfenceFeb 1, 2018
- CVE-2017-879039Monitor
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
CriticalCVSS 9.8No exploitEPSS 1%accellion · file transfer applianceMay 5, 2017
- CVE-2024-3386839Monitor
An issue was discovered in linqi before 1.4.0.1 on Windows.
CriticalCVSS 9.8No exploitEPSS 1%linqi · linqiMay 14, 2024
- CVE-2015-1002739Monitor
hydrian TTRSS-Auth-LDAP Username ldap injection
CriticalCVSS 9.8No exploitEPSS 1%ttrrs-auth-ldap project · ttrrs-auth-ldapJan 7, 2023
- CVE-2026-3328939Monitor
SuiterCRM has LDAP Filter Injection in Authentication Module
CriticalCVSS 9.8No exploitEPSS 1%suitecrm · suitecrmMar 19, 2026
- CVE-2024-5485239Monitor
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectio
CriticalCVSS 9.8No exploitEPSS 1%sismics · teedyJan 29, 2025
- CVE-2023-690539Monitor
Jahastech NxFilter Bind Request ldap injection
CriticalCVSS 9.8No exploitEPSS 1%nxfilter · nxfilterDec 17, 2023
- CVE-2026-4493039Monitor
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
CriticalCVSS 9.8No exploitEPSS 1%apache · cxfMay 22, 2026
- CVE-2026-4661937Monitor
OpenAM Authentication Bypass via MSISDN LDAP Injection
CriticalCVSS 9.3No exploitEPSS 1%openidentityplatform · openamSep 15, 2026
- CVE-2026-4191936Monitor
Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
CriticalCVSS 9.1No exploitEPSS 1%apache · ofbizMay 19, 2026
- CVE-2024-5684136Monitor
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).
CriticalCVSS 9.1No exploitEPSS 0%siemens · mendix ldapJan 14, 2025
- CVE-2026-9405336Monitor
Apache MINA SSHD: LDAP injection in sshd-ldap
CriticalCVSS 9.1No exploitapache software foundation · apache mina sshdToday
- CVE-2022-425435Monitor
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
HighCVSS 8.8No exploitEPSS 1%fedoraproject · sssdFeb 1, 2023
- CVE-2026-4730335Monitor
ASP.NET Core Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · .netJul 14, 2026
- CVE-2026-5822235Monitor
Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes
HighCVSS 8.8No exploitEPSS 1%red hat · red hat enterprise linux 10Jul 30, 2026
- CVE-2026-4926835Monitor
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
HighCVSS 8.8Proof of conceptEPSS 1%apache · shiroJun 17, 2026
- CVE-2026-3996235Monitor
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
HighCVSS 8.8No exploitEPSS 1%misp-project · mispApr 9, 2026
- CVE-2025-4820835Monitor
Apache HertzBeat (incubating): Jmx JNDI injection vulnerability
HighCVSS 8.8No exploitEPSS 1%apache · hertzbeatSep 9, 2025
- CVE-2026-1369635Monitor
LDAP Injection in HAVELSAN's Liman MYS
HighCVSS 8.8No exploitEPSS 1%havelsan inc. · liman mysJul 7, 2026
- CVE-2026-2556034Monitor
WeKan < 8.19 LDAP Authentication Filter Injection
HighCVSS 8.7No exploitEPSS 1%wekan project · wekanFeb 7, 2026
- CVE-2026-4045934Monitor
LDAP Injection in PAC4J
HighCVSS 8.7No exploitEPSS 1%pac4j · pac4jApr 17, 2026