Neo4j
First CVE: Sep 11, 2025Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
4.0
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Neo4j as a CNA, 50.0% affect products that Neo4j develops as a vendor.
50.0%
50.0%
Self-reported: 4Third-party: 4
Of all the CVEs published that affect products developed by Neo4j, 28.6% are self-published by Neo4j as a CNA.
28.6%
71.4%
Self-published: 4Published by other CNAs: 10
Trends Over Time
The number and severity of CVEs published by Neo4j over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2025
10 months ago
Most Recent CVE
Mar 11, 2026
135 days ago
Top CVEs
All CVEs published by Neo4j as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1524CRITICAL An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:
If a neo4j admin c | Mar 11, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-10193HIGH DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally | Sep 11, 2025 | 7.4 | 25 | NO | NO |
CVE-2026-1497HIGH Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:
an admin that intend | Mar 11, 2026 | 7.2 | 24 | NO | NO |
CVE-2026-1471MEDIUM Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authen | Mar 11, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-1337MEDIUM Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treat | Feb 6, 2026 | 5.4 | 22 | NO | NO |
CVE-2025-11602MEDIUM Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The at | Oct 31, 2025 | 6.3 | 22 | NO | NO |
CVE-2026-1622MEDIUM Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local l | Feb 4, 2026 | 4.8 | 18 | NO | NO |
Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database. | Jan 22, 2026 | 1.3 | 13 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA8 CVEs
13%
50%
25%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low4 (50.0%)
High1 (12.5%)
None3 (37.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Neo4j as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Neo4j as a CNA — matched by CVE ID, not by organization name.