Mongoose
Mongoosejs · 6 CVEs
CVE-2026-42334
HIGH
Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
May 14, 2026
CVE-2025-23061
CRITICAL
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. N…
Jan 15, 2025
CVE-2024-53900
HIGH
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
Dec 2, 2024
CVE-2023-3696
CRITICAL
Prototype Pollution in automattic/mongoose
Jul 17, 2023
CVE-2022-2564
CRITICAL
Prototype Pollution in automattic/mongoose
Jul 28, 2022
CVE-2019-17426
CRITICAL
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query ob…
Oct 10, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-42334 | Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection | HIGH | 0.46% | May 14, 2026 |
| CVE-2025-23061 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an inc… | CRITICAL | 7.28% | Jan 15, 2025 |
| CVE-2024-53900 | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. | HIGH | 3.98% | Dec 2, 2024 |
| CVE-2023-3696 | Prototype Pollution in automattic/mongoose | CRITICAL | 1.21% | Jul 17, 2023 |
| CVE-2022-2564 | Prototype Pollution in automattic/mongoose | CRITICAL | 32.68% | Jul 28, 2022 |
| CVE-2019-17426 | Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignor… | CRITICAL | 1.66% | Oct 10, 2019 |
Showing 1 to 6 of 6 CVEs