Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpldapadmin Project

First CVE: Aug 30, 2005Active for: 21 yearsTotal CVEs: 12
52.0
VTI Score
TOP TARGET

Phpldapadmin Project maintains a lightweight web-based LDAP directory administration tool that, despite a narrow product focus, occupies a niche role in directory-service management infrastructure and attracts significant public exploit tooling. The vendor's vulnerability profile centers on input-handling weaknesses spanning cross-site scripting, path traversal, code injection, and command injection—attack vectors endemic to web interfaces that process user-supplied LDAP queries and filesystem paths—and while a meaningful share of its disclosures reach serious severity, the durable signal is the recurring appeal to public exploit development. Defenders deploying this tool should restrict web-interface access, apply patches promptly, and monitor for abuse of its directory-query and file-access surface; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpldapadmin Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2005
20 years ago
Most Recent CVE
Dec 11, 2020
2,051 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-4075HIGH
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in
Nov 2, 20117.570NOYES
CVE-2009-4427HIGH
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
Dec 28, 20097.535NOYES
CVE-2018-12689CRITICAL
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
Jun 22, 20189.830NONO
CVE-2017-11107MEDIUM
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
Jul 8, 20176.129NOYES
CVE-2005-2792MEDIUM
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page param
Sep 2, 20055.029NOYES
CVE-2012-0834MEDIUM
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parame
Feb 11, 20124.327NOYES
CVE-2011-4074MEDIUM
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.
Nov 2, 20114.326NOYES
CVE-2006-2016LOW
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a)
Apr 25, 20062.625NOYES
CVE-2011-4082HIGH
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw
Nov 26, 20197.524NONO
CVE-2005-2793HIGH
PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.
Sep 2, 20057.522NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
42%
42%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (33.3%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None2 (16.7%)
Unknown8 (66.7%)
Required2 (16.7%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None3 (25.0%)
Unknown8 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 98th percentile
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
6 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpldapadmin Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpldapadmin Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpldapadmin Project's Products

View all 3 CNAs →

Top CWEs