l
lemonldap
Security Risk Profile
88
/100
criticalSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 10, 2024 to present
5
Total CVEs
4
Critical+High
0
Exploited
4
Unpatched
Threat Assessment
Avg CVSS
8.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
88/100
critical
Severity Distribution
Critical
2High
2Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
OS Command Injection
1
2
Command Injection
1
3
XSS
1
Most Affected Products
1. LemonLDAP NG3
2. LemonLDAP Lemonldap::NG::Portal1
3. LemonLDAP LemonLDAP::NG1
Recent Vulnerabilities
See more →CVE-2026-19349
CVSS 9.8critical
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
Aug 16, 2026🔧 No Patch
CVE-2025-59518
CVSS 8.0high
Sep 17, 2025🔧 No Patch
CVE-2024-52947
CVSS 5.4medium
Nov 18, 2024🔧 No Patch
CVE-2024-52946
CVSS 8.8high
Nov 18, 2024🔧 No Patch
CVE-2021-35473
CVSS 9.1critical
Nov 10, 2024🔧 No Patch
Monitor lemonldap in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.