mongoosejs mongoose CVE Vulnerabilities (6)

CVEs: 6 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting mongoosejs mongoose (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-42334 Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), [email protected] 7.5 0.27% 2026-05-14 2026-06-17
CVE-2025-23061 Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. [email protected] 9.0 7.03% 2025-01-15 2026-06-17
CVE-2024-53900 Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. [email protected] 9.1 3.91% 2024-12-02 2026-06-17
CVE-2023-3696 Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4. [email protected] 9.8 1.01% 2023-07-16 2026-06-17
CVE-2022-2564 Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. [email protected] 9.8 32.68% 2022-07-28 2026-06-17
CVE-2019-17426 Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project). [email protected] 9.1 1.66% 2019-10-09 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence