CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
73 vulnerabilities with CWE-90
CVE-2026-29131
HIGH
SEPPmail Secure Email Gateway - PGP Decryption Recipient LDAP Injection
CVSS 7.5
CVE-2026-27860
LOW
OX Dovecot Pro <3.1.0 - Auth Bypass
CVSS 3.7
CVE-2026-33751
MEDIUM
n8n Vulnerable to LDAP Filter Injection in LDAP Node
CVSS 4.8
CVE-2026-33289
HIGH
SuiterCRM has LDAP Filter Injection in Authentication Module
CVSS 8.8
CVE-2026-31828
HIGH
Parse Server <9.5.2-alpha.13/8.6.26 - LDAP Injection
CVSS 8.8
CVE-2026-25560
CRITICAL
WeKan < 8.19 - LDAP Injection in Authentication Filter
CVSS 9.8
CVE-2026-1498
HIGH
WatchGuard Fireware OS - Info Disclosure
CVE-2026-24130
MEDIUM
Moonraker < 0.10.0 - LDAP Injection via Login Endpoint
CVSS 5.3
CVE-2026-21880
MEDIUM
kanboard < 1.2.49 - LDAP Injection in Authentication Mechanism
CVSS 5.3
CVE-2025-67493
HIGH
homarr < 1.45.3 - Authenticated Privilege Escalation via LDAP Query Injection
CVSS 7.5
CVE-2025-12764
HIGH
pgAdmin <= 9.9 - LDAP Injection via Username Parameter
CVSS 7.5
CVE-2025-35431
MEDIUM
CISA Thorium 1.0.0-1.1.0 - Authenticated LDAP Injection
CVSS 5.4
CVE-2025-48208
HIGH
Apache HertzBeat <= 1.7.2 - Authenticated LDAP Injection via Custom Commands
CVSS 8.8
CVE-2025-52575
MEDIUM
EspoCRM < 9.1.7 - Unauthenticated Blind LDAP Injection via Wildcard Character
CVSS 6.5
CVE-2025-4573
MEDIUM
Mattermost 9.11.0-9.11.13 10.5.0-10.5.4 10.6.0-10.6.3 10.7.0-10.7.1 - LDAP Injection via Group ID
CVSS 4.1
CVE-2025-27686
LOW
Dell Unisphere for PowerMax < 9.2.4.15 - Authenticated LDAP Injection
CVSS 2.7
CVE-2025-27631
MEDIUM
Hitachi Energy TRMTracker 6.2-6.2.03 and 6.3 - LDAP Injection
CVSS 6.5
CVE-2024-54852
CRITICAL
Teedy 1.9-1.12 - Unauthenticated LDAP Injection via Login Username Field
CVSS 9.8
CVE-2024-56841
HIGH
Mendix LDAP <V1.1.2 - LDAP Injection
CVSS 7.4
CVE-2024-27310
MEDIUM
Zoho ManageEngine ASDSelfService Plus <6401 - DoS
CVSS 5.3
CVE-2024-33868
CRITICAL
linqi < 1.4.0.1 - LDAP Injection
CVSS 9.8
CVE-2023-51446
MEDIUM
GLPI 0.70-10.0.11 - LDAP Injection via Authentication Form
CVSS 5.9
CVE-2023-31025
MEDIUM
NVIDIA DGX A100 BMC - Info Disclosure
CVSS 6.5
CVE-2023-29050
HIGH
LDAP contacts provider - Info Disclosure
CVSS 7.6
CVE-2023-6905
MEDIUM
Jahastech NxFilter 4.3.2.5 - LDAP Injection in Bind Request Handler
CVSS 4.3
Details
Vulnerabilities
73