Mongo Express is a web-based administrative interface for MongoDB that, despite a narrow product footprint, occupies a notable position in database management tooling and may be exposed to internet-facing attack surfaces. The observed vulnerabilities center on its single administrative product and reflect the input-handling and authentication demands of a management console. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mongo Express Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10758CRITICAL mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non- | Dec 24, 2019 | 9.9 | 97 | YES | YES |
CVE-2020-24391CRITICAL mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769. | Mar 30, 2021 | 9.8 | 79 | NO | YES |
CVE-2021-23372HIGH All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash. | Apr 13, 2021 | 7.5 | 22 | NO | NO |
CVE-2021-21422MEDIUM mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, wh | Jun 21, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-52555MEDIUM In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection. | Mar 1, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mongo Express Project.
Media articles that mention a CVE ID that affects a product developed by Mongo Express Project — matched by CVE ID, not by vendor name.