CWE-90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

64 vulnerabilities with CWE-90
CVE-2025-67493 HIGH
homarr < 1.45.3 - Authenticated Privilege Escalation via LDAP Query Injection
CVSS 7.5
CVE-2025-12764 HIGH
pgAdmin <= 9.9 - LDAP Injection via Username Parameter
CVSS 7.5
CVE-2025-35431 MEDIUM
CISA Thorium 1.0.0-1.1.0 - Authenticated LDAP Injection
CVSS 5.4
CVE-2025-48208 HIGH
Apache HertzBeat <= 1.7.2 - Authenticated LDAP Injection via Custom Commands
CVSS 8.8
CVE-2025-52575 MEDIUM
EspoCRM < 9.1.7 - Unauthenticated Blind LDAP Injection via Wildcard Character
CVSS 6.5
CVE-2025-4573 MEDIUM
Mattermost 9.11.0-9.11.13 10.5.0-10.5.4 10.6.0-10.6.3 10.7.0-10.7.1 - LDAP Injection via Group ID
CVSS 4.1
CVE-2025-27686 LOW
Dell Unisphere for PowerMax < 9.2.4.15 - Authenticated LDAP Injection
CVSS 2.7
CVE-2025-27631 MEDIUM
Hitachi Energy TRMTracker 6.2-6.2.03 and 6.3 - LDAP Injection
CVSS 6.5
CVE-2024-54852 CRITICAL
Teedy 1.9-1.12 - Unauthenticated LDAP Injection via Login Username Field
CVSS 9.8
CVE-2024-56841 HIGH
Mendix LDAP <V1.1.2 - LDAP Injection
CVSS 7.4
CVE-2024-27310 MEDIUM
Zoho ManageEngine ASDSelfService Plus <6401 - DoS
CVSS 5.3
CVE-2024-33868 CRITICAL
linqi < 1.4.0.1 - LDAP Injection
CVSS 9.8
CVE-2023-51446 MEDIUM
GLPI 0.70-10.0.11 - LDAP Injection via Authentication Form
CVSS 5.9
CVE-2023-31025 MEDIUM
NVIDIA DGX A100 BMC - Info Disclosure
CVSS 6.5
CVE-2023-29050 HIGH
LDAP contacts provider - Info Disclosure
CVSS 7.6
CVE-2023-6905 MEDIUM
Jahastech NxFilter 4.3.2.5 - LDAP Injection in Bind Request Handler
CVSS 4.3
CVE-2023-3447 HIGH
Active Directory Integration / LDAP Integration <= 4.1.5 - Authenticated LDAP Injection via Username Parameter
CVSS 7.6
CVE-2023-28853 HIGH
Mastodon <3.5.8, <4.0.4, <4.1.2 - SQL Injection
CVSS 7.7
CVE-2022-4254 HIGH
sssd 1.15.3-2.3.1 - LDAP Injection via Certificate Data in LDAP Filters
CVSS 8.8
CVE-2022-45910 MEDIUM
Apache ManifoldCF < 2.23 - LDAP Injection in ActiveDirectory and Sharepoint Authority Connectors
CVSS 5.3
CVE-2021-43782 MEDIUM
Tuleap < 13.2.99.83 and 13.1-1-13.1-5 - LDAP Injection via User ldap_id Attribute
CVSS 6.7
CVE-2021-41276 MEDIUM
Tuleap < 13.2.99.31 and 13.1-1-13.1-5 - LDAP Injection via User ldap_id Attribute
CVSS 6.7
CVE-2021-43350 CRITICAL
Apache Traffic Control - Info Disclosure
CVSS 9.8
CVE-2021-41232 HIGH
Thunderdome <1.16.3 - Command Injection
CVSS 8.1
CVE-2021-32651 LOW
OneDev <4.4.1 - Blind LDAP Injection
CVSS 3.1
Details
Vulnerabilities 64