VendorsMoment.jsmomentany version
Vulnerabilities

Moment.js Moment any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2016-4055
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
Published 2017-01-23 · Modified
7.8EPSS 0.099
CVE-2022-24785
Path Traversal in Moment.js
Published 2022-04-04 · Modified
7.5EPSS 0.139
CVE-2022-31129
Inefficient Regular Expression Complexity in moment
Published 2022-07-06 · Modified
7.5EPSS 0.056
CVE-2017-18214
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
Published 2018-03-04 · Modified
7.5EPSS 0.036