Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lemonldap Ng

First CVE: Jan 1, 2013Active for: 14 yearsTotal CVEs: 32

Lemonldap Ng is a centralized authentication and access-management platform that, despite a narrow product scope, occupies a prominent position in federated identity and single sign-on deployments across educational and enterprise networks. Vulnerabilities affecting this vendor cluster around its core authentication and session-management functions, reflecting the sensitivity of the access-control boundary it enforces. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lemonldap Ng over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2013
13 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-40874CRITICAL
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG insta
Jul 18, 20229.831NONO
CVE-2020-24660CRITICAL
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalize
Sep 14, 20209.831NONO
CVE-2019-15941CRITICAL
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable,
Sep 25, 20199.830NONO
CVE-2019-12046CRITICAL
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
May 22, 20199.830NONO
CVE-2023-28862CRITICAL
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers t
Mar 31, 20239.829NONO
CVE-2019-19791CRITICAL
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG set
May 29, 20239.828NONO
CVE-2019-13031HIGH
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and
Jun 28, 20198.127NONO
CVE-2020-36659HIGH
In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration
Jan 27, 20238.126NONO
CVE-2020-36658HIGH
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the N
Jan 27, 20238.126NONO
CVE-2025-59518HIGH
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an adminis
Sep 17, 20258.025NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
18%
47%
35%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (94.1%)
Unknown1 (5.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (64.7%)
High5 (29.4%)
Unknown1 (5.9%)
User Interaction
None15 (88.2%)
Unknown1 (5.9%)
Required1 (5.9%)
Privileges Required
Low2 (11.8%)
High1 (5.9%)
None13 (76.5%)
Unknown1 (5.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lemonldap Ng.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lemonldap Ng — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lemonldap Ng's Products

View all 1 CNAs →

Top CWEs