mongoosejs records
6 published records for vendor mongoosejs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2022-2564No exploit | Prototype Pollution in automattic/mongoosemongoosejs · mongoose · CWE-1321 | Critical9.8 | — | 32.7% | Jul 28, 2022 |
41Plan | CVE-2025-23061Proof of concept | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection.mongoosejs · mongoose · CWE-94 | Critical9.8 | — | 7.3% | Jan 15, 2025 |
39Monitor | CVE-2023-3696No exploit | Prototype Pollution in automattic/mongoosemongoosejs · mongoose · CWE-1321 | Critical9.8 | — | 1.2% | Jul 16, 2023 |
37Monitor | CVE-2024-53900Proof of concept | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.mongoosejs · mongoose · CWE-89 | Critical9.1 | — | 4.0% | Dec 2, 2024 |
36Monitor | CVE-2019-17426No exploit | Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontypemongoosejs · mongoose | Critical9.1 | — | 1.7% | Oct 9, 2019 |
30Monitor | CVE-2026-42334No exploit | Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injectionmongoosejs · mongoose · CWE-74 | High7.5 | — | 0.5% | May 14, 2026 |
- CVE-2022-256449Plan
Prototype Pollution in automattic/mongoose
CriticalCVSS 9.8No exploitEPSS 33%mongoosejs · mongooseJul 28, 2022
- CVE-2025-2306141Plan
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection.
CriticalCVSS 9.8Proof of conceptEPSS 7%mongoosejs · mongooseJan 15, 2025
- CVE-2023-369639Monitor
Prototype Pollution in automattic/mongoose
CriticalCVSS 9.8No exploitEPSS 1%mongoosejs · mongooseJul 16, 2023
- CVE-2024-5390037Monitor
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
CriticalCVSS 9.1Proof of conceptEPSS 4%mongoosejs · mongooseDec 2, 2024
- CVE-2019-1742636Monitor
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype
CriticalCVSS 9.1No exploitEPSS 2%mongoosejs · mongooseOct 9, 2019
- CVE-2026-4233430Monitor
Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
HighCVSS 7.5No exploitEPSS 0%mongoosejs · mongooseMay 14, 2026