Mongo Express
Vendor:
First CVE: Dec 24, 2019 · Active for 6 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
20.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Mongo Express over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2019
6 years ago
Most Recent CVE
Mar 1, 2024
878 days ago
CVE Severity & Scoring
Mongo Express5 CVEs
40%
20%
40%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10758CRITICAL mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non- | Dec 24, 2019 | 9.9 | 97 | YES | YES |
CVE-2020-24391CRITICAL mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769. | Mar 30, 2021 | 9.8 | 79 | NO | YES |
CVE-2021-23372HIGH All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash. | Apr 13, 2021 | 7.5 | 22 | NO | NO |
CVE-2021-21422MEDIUM mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, wh | Jun 21, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-52555MEDIUM In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection. | Mar 1, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
1 CVE
20.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
40.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Mongo Express
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.2 | 1 | 6.1 | 0.2% | 0 | 0 |
| 1.0.0 | 1 | 6.1 | 1.6% | 0 | 0 |