cbcvebase.
CVE-2025-31510
published 2026-01-16

CVE-2025-31510: In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page)…

PriorityP341high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.38%
30.3th percentile
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianlemonldap-ng< lemonldap-ng 2.16.1+ds-deb12u6 (bookworm)lemonldap-ng 2.16.1+ds-deb12u6 (bookworm)
lemonldap-nglemonldap_ng>= 2.0.8 < 2.16.52.16.5
lemonldap-nglemonldap_ng>= 2.17.0 < 2.21.02.21.0

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.