Lemonldap Ng is a centralized authentication and access-management platform that, despite a narrow product scope, occupies a prominent position in federated identity and single sign-on deployments across educational and enterprise networks. Vulnerabilities affecting this vendor cluster around its core authentication and session-management functions, reflecting the sensitivity of the access-control boundary it enforces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lemonldap Ng over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40874CRITICAL An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG insta | Jul 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-24660CRITICAL An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalize | Sep 14, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-15941CRITICAL OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, | Sep 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-12046CRITICAL LemonLDAP::NG -2.0.3 has Incorrect Access Control. | May 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-28862CRITICAL An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers t | Mar 31, 2023 | 9.8 | 29 | NO | NO |
CVE-2019-19791CRITICAL In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG set | May 29, 2023 | 9.8 | 28 | NO | NO |
CVE-2019-13031HIGH LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and | Jun 28, 2019 | 8.1 | 27 | NO | NO |
CVE-2020-36659HIGH In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration | Jan 27, 2023 | 8.1 | 26 | NO | NO |
CVE-2020-36658HIGH In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the N | Jan 27, 2023 | 8.1 | 26 | NO | NO |
CVE-2025-59518HIGH In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an adminis | Sep 17, 2025 | 8.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lemonldap Ng.
Media articles that mention a CVE ID that affects a product developed by Lemonldap Ng — matched by CVE ID, not by vendor name.