MongoDB / PHP Driver
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-96745 | PHP object injection via unsuppressible __pclass class inference in command monitoring events | MEDIUM | 6.3 | Sep 24, 2026 |
| CVE-2026-84968 | Heap out-of-bounds read via corrupt nested BSON in field path error message | MEDIUM | 6.9 | Sep 3, 2026 |
| CVE-2026-6811 | PHP Stack Exhaustion | MEDIUM | 6.0 | May 14, 2026 |
| CVE-2025-12119 | Bulk write with options may read invalid memory | MEDIUM | 6.9 | Nov 18, 2025 |
| CVE-2024-7553 | Accessing Untrusted Directory May Allow Local Privilege Escalation | HIGH | 7.8 | Aug 7, 2024 |
| CVE-2021-32050 | Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an application | HIGH | 7.5 | Aug 29, 2023 |
Showing 1 to 5 of 5 CVEs