Vendorsmongo-express Projectmongo-expressany version
Vulnerabilities

mongo-express Project mongo-express any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-10758
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
Published 2019-12-24 · Analyzed
9.9KEVEPSS 0.847
CVE-2020-24391
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Published 2021-03-30 · Modified
9.8EPSS 0.745
CVE-2021-21422
XSS Vulnerability in mongo-express
Published 2021-06-21 · Modified
8.1EPSS 0.016
CVE-2021-23372
Denial of Service (DoS)
Published 2021-04-13 · Modified
7.5EPSS 0.009