lemonldap
Security Risk Profile
62
/100
highSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 10, 2024 to present
5
Total CVEs
3
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
7.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
62/100
high
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
1High
2Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
OS Command Injection
1
2
Command Injection
1
3
XSS
1
Most Affected Products
1. LemonLDAP NG3
2. LemonLDAP Lemonldap::NG::Portal1
3. LemonLDAP LemonLDAP::NG1
Recent Vulnerabilities
See more →CVE-2026-19349
unknown
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
8/16/2026🔧 No Patch
CVE-2025-59518
CVSS 8.0high
9/17/2025🔧 No Patch
CVE-2024-52947
CVSS 5.4medium
11/18/2024🔧 No Patch
CVE-2024-52946
CVSS 8.8high
11/18/2024🔧 No Patch
CVE-2021-35473
CVSS 9.1critical
11/10/2024🔧 No Patch
Monitor lemonldap in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.