CWE-90: CWE-90

14
Total CVEs
3
Critical
4
High
7.2
Avg CVSS

Yearly Trend

2026
4
2025
6
2024
2
2023
1
2021
1

Top Affected Vendors

1 Apache 1
2 Kanboard 1
3 Joinmastodon 1
4 Mattermost 1
5 Cisa 1
6 Pgadmin 1
7 Sismics 1
8 Open Xchange 1
9 Linqi 1
10 Arksine 1

All CWE-90 CVEs (14)

CVE-2024-54852
9.8

This LDAP injection vulnerability in Teedy allows unauthenticated attackers to manipulate LDAP queries through the login form's username field. Attack...

Jan 29, 2025
CVE-2024-33868
9.8

This LDAP injection vulnerability in linqi on Windows allows attackers to manipulate LDAP queries, potentially leading to unauthorized access or data ...

May 14, 2024
CVE-2021-43350
9.8

CVE-2021-43350 is an LDAP injection vulnerability in Apache Traffic Control Traffic Ops that allows unauthenticated attackers to manipulate LDAP filte...

Nov 11, 2021
CVE-2023-28853
7.7

This vulnerability allows attackers to perform LDAP injection attacks on Mastodon instances configured with LDAP authentication. By manipulating login...

Apr 4, 2023
CVE-2023-29050
7.6

This LDAP injection vulnerability in OX App Suite's optional LDAP contacts provider allows privileged users to inject malicious LDAP filter strings. T...

Jan 8, 2024
CVE-2025-12764
7.5

pgAdmin versions up to 9.9 have an LDAP injection vulnerability in the authentication flow that allows attackers to inject special LDAP characters in ...

Nov 13, 2025
CVE-2024-56841
7.4

Mendix LDAP module versions before 1.1.2 are vulnerable to LDAP injection attacks. This allows unauthenticated remote attackers to bypass username ver...

Jan 14, 2025
CVE-2025-27631
6.5

CVE-2025-27631 is an LDAP injection vulnerability in the TRMTracker web application that allows attackers to inject malicious LDAP queries. This could...

Mar 25, 2025
CVE-2025-35431
5.4

CVE-2025-35431 is an LDAP injection vulnerability in CISA Thorium that allows authenticated attackers to modify LDAP authorization data like group mem...

Sep 17, 2025
CVE-2026-24130
5.3

Moonraker versions 0.9.3 and below with LDAP enabled are vulnerable to LDAP injection attacks through the login endpoint. Attackers can use error mess...

Jan 22, 2026
CVE-2026-21880
5.3

Kanboard versions 1.2.48 and below contain an LDAP injection vulnerability in the authentication mechanism. Attackers can manipulate LDAP search filte...

Jan 8, 2026
CVE-2025-4573
4.1

This vulnerability allows authenticated Mattermost administrators with specific permissions to perform LDAP search filter injection when linking LDAP ...

Jun 11, 2025
CVE-2026-25560
N/A

CVE-2026-25560 is an LDAP filter injection vulnerability in WeKan versions before 8.19. Attackers can manipulate LDAP queries during authentication by...

Feb 7, 2026
CVE-2026-1498
N/A

An LDAP injection vulnerability in WatchGuard Fireware OS allows remote attackers to retrieve sensitive information from connected LDAP servers throug...

Jan 30, 2026

About CWE-90 (CWE-90)

Our database tracks 14 CVEs classified as CWE-90, with 3 rated critical and 4 rated high severity. The average CVSS score for CWE-90 vulnerabilities is 7.2.

External reference: View CWE-90 on MITRE CWE →

Monitor CWE-90 Vulnerabilities

Get alerted when new CWE-90 CVEs affect your infrastructure.

Start Monitoring Free