Skip to content
Noroxi

CWE-90 · 85 records

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

CVEs in this class

86 records

  • CVE-2016-9299
    68This week

    The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized

    CriticalCVSS 9.8WeaponizedEPSS 97%

    jenkins · jenkinsJan 12, 2017

  • In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

    CriticalCVSS 9.8No exploitEPSS 7%

    joomla · joomla\!Sep 20, 2017

  • LDAP filter injection vulnerability in Traffic Ops

    CriticalCVSS 9.8No exploitEPSS 5%

    apache · traffic controlNov 11, 2021

  • The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside

    CriticalCVSS 9.6No exploitEPSS 2%

    open-xchange · ox app suiteJan 8, 2024

  • CVE-2011-4069
    39Monitor

    html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentic

    CriticalCVSS 9.8No exploitEPSS 2%

    packetfence · packetfenceFeb 1, 2018

  • CVE-2017-8790
    39Monitor

    An issue was discovered on Accellion FTA devices before FTA_9_12_180.

    CriticalCVSS 9.8No exploitEPSS 1%

    accellion · file transfer applianceMay 5, 2017

  • An issue was discovered in linqi before 1.4.0.1 on Windows.

    CriticalCVSS 9.8No exploitEPSS 1%

    linqi · linqiMay 14, 2024

  • hydrian TTRSS-Auth-LDAP Username ldap injection

    CriticalCVSS 9.8No exploitEPSS 1%

    ttrrs-auth-ldap project · ttrrs-auth-ldapJan 7, 2023

  • SuiterCRM has LDAP Filter Injection in Authentication Module

    CriticalCVSS 9.8No exploitEPSS 1%

    suitecrm · suitecrmMar 19, 2026

  • When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectio

    CriticalCVSS 9.8No exploitEPSS 1%

    sismics · teedyJan 29, 2025

  • CVE-2023-6905
    39Monitor

    Jahastech NxFilter Bind Request ldap injection

    CriticalCVSS 9.8No exploitEPSS 1%

    nxfilter · nxfilterDec 17, 2023

  • Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository

    CriticalCVSS 9.8No exploitEPSS 1%

    apache · cxfMay 22, 2026

  • OpenAM Authentication Bypass via MSISDN LDAP Injection

    CriticalCVSS 9.3No exploitEPSS 1%

    openidentityplatform · openamSep 15, 2026

  • Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction

    CriticalCVSS 9.1No exploitEPSS 1%

    apache · ofbizMay 19, 2026

  • A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).

    CriticalCVSS 9.1No exploitEPSS 0%

    siemens · mendix ldapJan 14, 2025

  • Apache MINA SSHD: LDAP injection in sshd-ldap

    CriticalCVSS 9.1No exploit

    apache software foundation · apache mina sshdToday

  • CVE-2022-4254
    35Monitor

    sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters

    HighCVSS 8.8No exploitEPSS 1%

    fedoraproject · sssdFeb 1, 2023

  • ASP.NET Core Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · .netJul 14, 2026

  • Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes

    HighCVSS 8.8No exploitEPSS 1%

    red hat · red hat enterprise linux 10Jul 30, 2026

  • Apache Shiro: LDAP DN Injection in DefaultLdapRealm

    HighCVSS 8.8Proof of conceptEPSS 1%

    apache · shiroJun 17, 2026

  • LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable

    HighCVSS 8.8No exploitEPSS 1%

    misp-project · mispApr 9, 2026

  • Apache HertzBeat (incubating): Jmx JNDI injection vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    apache · hertzbeatSep 9, 2025

  • LDAP Injection in HAVELSAN's Liman MYS

    HighCVSS 8.8No exploitEPSS 1%

    havelsan inc. · liman mysJul 7, 2026

  • WeKan < 8.19 LDAP Authentication Filter Injection

    HighCVSS 8.7No exploitEPSS 1%

    wekan project · wekanFeb 7, 2026

  • LDAP Injection in PAC4J

    HighCVSS 8.7No exploitEPSS 1%

    pac4j · pac4jApr 17, 2026

All vulnerability classes