VendorsLDAP Account Managerldap_account_managerany version
Vulnerabilities

LDAP Account Manager (LAM) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-31084
Unauthenticated Remote Code Execution in ldap-account-manager
Published 2022-06-27 · Modified
9.0EPSS 0.025
CVE-2022-31086
Incorrect Regular Expressions in ldap-account-manager
Published 2022-06-27 · Modified
8.8EPSS 0.023
CVE-2018-8764
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.
Published 2018-03-27 · Modified
8.8EPSS 0.013
CVE-2026-27895
LAM has incorrect regular expression in PDF export component that allows user to upload files of any type
Published 2026-03-17 · Analyzed
8.8EPSS 0.008
CVE-2026-27894
LAM has Authenticated Local File Inclusion (LFI) in PDF export
Published 2026-03-17 · Analyzed
8.8EPSS 0.007
CVE-2022-24851
Stored XSS and path traversal in LDAPAccountManager/lam
Published 2022-04-15 · Modified
8.1EPSS 0.011
CVE-2024-23333
LAM vulnerable to Authenticated Remote Code Execution
Published 2024-03-18 · Analyzed
7.9EPSS 0.179
CVE-2022-31087
Incorrect Default Permissions in ldap-account-manager
Published 2022-06-27 · Modified
7.8EPSS 0.004
CVE-2022-31088
Unauthenticated LDAP Injection in ldap-account-manager
Published 2022-06-27 · Modified
6.5EPSS 0.013
CVE-2018-8763
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
Published 2018-03-27 · Modified
6.1EPSS 0.015
CVE-2022-31085
Missing Encryption of Sensitive Data in ldap-account-manager
Published 2022-06-27 · Modified
6.1EPSS 0.003