Ldap Account Manager is a directory-management utility for LDAP systems that operates within a narrow product scope but occupies a specialized administrative role in identity infrastructure. Its vulnerability disclosures cluster around input-handling and validation weaknesses characteristic of web-based administrative tools. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ldap Account Manager over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27894HIGH LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was d | Mar 18, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-27895HIGH LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component doe | Mar 18, 2026 | 8.8 | 28 | NO | NO |
CVE-2022-31086HIGH LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular express | Jun 27, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-23333MEDIUM LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log files. Prior to vers | Mar 18, 2024 | 6.6 | 27 | NO | NO |
CVE-2022-31084HIGH LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM | Jun 27, 2022 | 8.1 | 27 | NO | NO |
CVE-2018-8764HIGH Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CS | Mar 27, 2018 | 8.8 | 27 | NO | NO |
CVE-2022-31087HIGH LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which | Jun 27, 2022 | 7.8 | 25 | NO | NO |
CVE-2012-1115MEDIUM A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php. | Dec 5, 2019 | 6.1 | 22 | NO | NO |
CVE-2012-1114MEDIUM A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid pa | Dec 5, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-8763MEDIUM Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the tem | Mar 27, 2018 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ldap Account Manager.
Media articles that mention a CVE ID that affects a product developed by Ldap Account Manager — matched by CVE ID, not by vendor name.