CVE-2025-31510: Lemonldap-NG Lemonldap::ng

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.

Affected products

  • Lemonldap-NG Lemonldap::ng: from 2.0.8, before 2.16.5 (fixed in 2.16.5); from 2.17.0, before 2.21.0 (fixed in 2.21.0)

Published 2026-01-16. Last modified 2026-06-17.