Skip to content
Noroxi

mongoosejs records

6 published records for vendor mongoosejs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

6 records
  • Prototype Pollution in automattic/mongoose

    CriticalCVSS 9.8No exploitEPSS 33%

    mongoosejs · mongooseJul 28, 2022

  • Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection.

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    mongoosejs · mongooseJan 15, 2025

  • CVE-2023-3696
    39Monitor

    Prototype Pollution in automattic/mongoose

    CriticalCVSS 9.8No exploitEPSS 1%

    mongoosejs · mongooseJul 16, 2023

  • Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

    CriticalCVSS 9.1Proof of conceptEPSS 4%

    mongoosejs · mongooseDec 2, 2024

  • Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype

    CriticalCVSS 9.1No exploitEPSS 2%

    mongoosejs · mongooseOct 9, 2019

  • Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

    HighCVSS 7.5No exploitEPSS 0%

    mongoosejs · mongooseMay 14, 2026