l
lemonldap-ng
Security Risk Profile
30
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 16 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 1, 2013 to present
16
Total CVEs
12
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
8.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
30/100
low
📈 1 in Last 30 Days
Severity Distribution
Critical
6High
6Medium
3Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
1
2
SSRF
1
3
XEE
1
Most Affected Products
1. lemonldap-ng Lemonldap\60
2. Debian Debian Linux9
3. ubuntu/libapache-session-ldap-perl4
4. debian/lemonldap-ng3
5. lemonldap-ng Apache\2
Recent Vulnerabilities
See more →https://seclists.org/oss-sec/2026/q3/505
unknown
CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 befo2.16.9, from 2.17.0 befo2.21.5, from 2.22.0 befo2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stod as an SSO session in the GitHub and LinkedIn backends
Aug 16, 2026🔧 No Patch
CVE-2024-48933
CVSS 6.1EPSS 0%medium
Oct 9, 2024🔧 No Patch
CVE-2023-44469
CVSS 4.3medium
Sep 29, 2023
CVE-2019-19791
CVSS 9.8critical
May 29, 2023🔧 No Patch
CVE-2022-37186
CVSS 5.9medium
Apr 16, 2023
CVE-2023-28862
CVSS 9.8critical
Mar 31, 2023
CVE-2020-36659
CVSS 8.1high
Jan 27, 2023
CVE-2020-36658
CVSS 8.1high
Jan 27, 2023
CVE-2021-40874
CVSS 9.8critical
Jul 17, 2022
CVE-2020-16093
CVSS 7.5high
Jul 17, 2022
Monitor lemonldap-ng in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.