Neo4j

First CVE: Sep 11, 2025Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
4.0
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Neo4j as a CNA, 50.0% affect products that Neo4j develops as a vendor.

50.0%
50.0%
Self-reported: 4Third-party: 4

Of all the CVEs published that affect products developed by Neo4j, 28.6% are self-published by Neo4j as a CNA.

28.6%
71.4%
Self-published: 4Published by other CNAs: 10

Trends Over Time

The number and severity of CVEs published by Neo4j over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2025
10 months ago
Most Recent CVE
Mar 11, 2026
135 days ago

Top CVEs

All CVEs published by Neo4j as a CNA, regardless of affected vendor or product.

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin c
Mar 11, 20269.829NONO
DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally
Sep 11, 20257.425NONO
Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intend
Mar 11, 20267.224NONO
Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authen
Mar 11, 20266.522NONO
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treat
Feb 6, 20265.422NONO
Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The at
Oct 31, 20256.322NONO
Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local l
Feb 4, 20264.818NONO
Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database.
Jan 22, 20261.313NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA8 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low4 (50.0%)
High1 (12.5%)
None3 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Neo4j as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Neo4j as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs