CWE-90— LDAP Injection
The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.— MITRE CWE catalog
95 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-90page 1 of 2
- CVE-2026-44930CRITICALCVSS 9.8EG 9.82026-05-26
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 o…
- CVE-2026-33289CRITICALCVSS 9.8EG 9.82026-03-20
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails…
- CVE-2026-25560CRITICALCVSS 9.8EG 9.82026-02-07
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker…
- CVE-2024-54852CRITICALCVSS 9.8EG 9.82025-01-29
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform …
- CVE-2024-33868CRITICALCVSS 9.8EG 9.82024-05-14
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
- CVE-2023-6905CRITICALCVSS 9.8EG 9.82023-12-18
A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2.5. This issue affects some unknown processing of the file user,adap.jsp?actionFlag=test&id=1 of the component Bind Request Handler. The manipu…
- CVE-2021-43350CRITICALCVSS 9.8EG 9.82021-11-11
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
- CVE-2011-4069CRITICALCVSS 9.8EG 9.82018-02-01
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.
- CVE-2017-14596CRITICALCVSS 9.8EG 9.82017-09-20
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
- CVE-2017-8790CRITICALCVSS 9.8EG 9.82017-05-05
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
- CVE-2016-9299CRITICALCVSS 9.8EG 9.82017-01-12
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
- CVE-2015-10027CRITICALCVSS 5.5EG 9.82023-01-07
A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality of the component Username Handler. The manipulation leads to ldap injection. Upgrading to…
- CVE-2026-39962CRITICALCVSS 9.6EG 9.62026-04-09
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAut…
- CVE-2026-46619CRITICALCVSS 9.3EG 9.32026-06-26
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the d…
- CVE-2026-94053CRITICALCVSS 9.1EG 9.12026-09-30
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap com…
- CVE-2026-49268CRITICALCVSS 9.1EG 9.12026-06-17
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 …
- CVE-2026-41919CRITICALCVSS 9.1EG 9.12026-05-19
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the i…
- CVE-2024-22319HIGHCVSS 8.1EG 8.92024-02-02
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145…
- CVE-2026-58222HIGHCVSS 8.8EG 8.82026-07-30
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribut…
- CVE-2026-47303HIGHCVSS 8.8EG 8.82026-07-14
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
- CVE-2026-13696HIGHCVSS 8.8EG 8.82026-07-07
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman MYS: before release.Master.1107.
- CVE-2026-40459HIGHCVSS 8.8EG 8.82026-04-17
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operatio…
- CVE-2026-31828HIGHCVSS 8.8EG 8.82026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) …
- CVE-2025-48208HIGHCVSS 8.8EG 8.82025-09-09
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by c…
- CVE-2022-4254HIGHCVSS 8.8EG 8.82023-02-01
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
- CVE-2023-3447HIGHCVSS 7.6EG 8.62023-06-29
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible f…
- CVE-2026-4256HIGHCVSS 8.2EG 8.22026-07-09
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026.
- CVE-2026-40193HIGHCVSS 8.2EG 8.22026-04-16
maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.Repla…
- CVE-2026-34578HIGHCVSS 8.2EG 8.22026-04-09
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker c…
- CVE-2026-75020HIGHCVSS 8.1EG 8.12026-08-27
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer ma…
- CVE-2026-44304HIGHCVSS 8.1EG 8.12026-05-12
Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inj…
- CVE-2021-41232HIGHCVSS 8.1EG 8.12021-11-02
Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is n…
- CVE-2019-11277HIGHCVSS 8.1EG 8.12019-09-23
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance cr…
- CVE-2023-28853HIGHCVSS 7.7EG 7.72023-04-04
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login …
- CVE-2020-5246HIGHCVSS 7.7EG 7.72020-07-14
Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and …
- CVE-2023-29050HIGHCVSS 7.6EG 7.62024-01-08
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the di…
- CVE-2026-19271HIGHCVSS 7.5EG 7.52026-08-26
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This issue affects Liderahenk: from 3.4.0 b…
- CVE-2026-11770HIGHCVSS 7.5EG 7.52026-07-31
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with el…
- CVE-2026-44671HIGHCVSS 7.5EG 7.52026-05-14
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames bef…
- CVE-2026-29138HIGHCVSS 7.5EG 7.52026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.
- CVE-2026-29131HIGHCVSS 7.5EG 7.52026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.
- CVE-2025-67493HIGHCVSS 7.5EG 7.52025-12-17
Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access to groups of other users due to missing sanitization of inputs in ldap search query. The v…
- CVE-2025-12764HIGHCVSS 7.5EG 7.52025-11-13
pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amou…
- CVE-2021-23335HIGHCVSS 7.5EG 7.52021-02-11
All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.
- CVE-2017-4927HIGHCVSS 7.5EG 7.52017-11-17
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
- CVE-2015-7294HIGHCVSS 7.5EG 7.52017-09-06
ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.
- CVE-2024-56841HIGHCVSS 7.4EG 7.42025-01-14
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to bypass username verification.
- CVE-2026-90979HIGHCVSS 7.3EG 7.32026-09-28
LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u, %dn, and %fqdn (drawn from the login name, the resolved user DN, and its fully qualified namesp…
- CVE-2026-41573HIGHCVSS 7.1EG 7.12026-06-22
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection …
- CVE-2026-1498HIGHCVSS 7.0EG 7.02026-01-30
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interfa…
Map vulnerabilities like CWE-90 to your infrastructure
EchelonGraph correlates every CVE — across CWE-90 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →