The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
Volume of CVEs assigned to CWE-90 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9299CRITICAL The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP quer | Jan 12, 2017 | 9.8 | 93 | NO | YES |
CVE-2026-44930CRITICAL An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
U | May 22, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-47303HIGH Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-13696HIGH Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection.
This issue affects Liman MYS: | Jul 7, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-49268CRITICAL A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated | Jun 17, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-4256HIGH Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection.
This issue affects Pas | Jul 9, 2026 | 8.2 | 35 | NO | NO |
CVE-2017-14596CRITICAL In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. | Sep 20, 2017 | 9.8 | 34 | NO | NO |
CVE-2026-41919CRITICAL Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are re | May 19, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-33289CRITICAL SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists | Mar 20, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-25560CRITICAL WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-rel | Feb 7, 2026 | 9.8 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.