Mongo Express

Vendor:

First CVE: Dec 24, 2019 · Active for 6 years

5
Total CVEs
More Total CVEs than 77% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
20.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Mongo Express over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2019
6 years ago
Most Recent CVE
Mar 1, 2024
878 days ago

CVE Severity & Scoring

Mongo Express5 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-
Dec 24, 20199.997YESYES
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Mar 30, 20219.879NOYES
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.
Apr 13, 20217.522NONO
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, wh
Jun 21, 20216.121NONO
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
Mar 1, 20246.118NONO

Exploit Exposure

Signals from CVEs in this product scope (5 CVEs).

CISA KEV
1 CVE
20.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
40.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (5 CVEs).

Media Mentions

Signals from CVEs in this product scope (5 CVEs).

Top CNAs Publishing CVEs For Mongo Express

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.0.216.10.2%00
1.0.016.11.6%00