Neo4j develops a graph database platform and associated query tooling that is increasingly deployed in enterprise environments for relationship-heavy analytics and knowledge-graph applications. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and concentrates in access-control and authentication weaknesses—including path traversal, authorization bypass, authentication flaws, XML external entity injection, and cross-site request forgery—that reflect the intersection of web-exposed APIs, file-system interaction, and multi-tenant deployment models. Defenders should treat Neo4j advisories as high-priority for environments where the database is internet-reachable or processes untrusted input; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neo4j over time
Of all the CVEs published by Neo4j as a CNA, 50.0% affect products that Neo4j develops as a vendor.
Of all the CVEs published that affect products developed by Neo4j, 28.6% are self-published by Neo4j as a CNA.
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34371CRITICAL Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this | Aug 5, 2021 | 9.8 | 35 | NO | NO |
CVE-2018-1000820CRITICAL neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential dat | Dec 20, 2018 | 10.0 | 30 | NO | NO |
CVE-2018-18389CRITICAL Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, | Oct 16, 2018 | 9.8 | 30 | NO | NO |
CVE-2026-1524CRITICAL An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:
If a neo4j admin c | Mar 11, 2026 | 9.8 | 29 | NO | NO |
CVE-2021-42767CRITICAL A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed | Mar 1, 2022 | 9.1 | 29 | NO | NO |
CVE-2021-34802HIGH A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privil | Jul 30, 2021 | 8.8 | 26 | NO | NO |
CVE-2023-23926HIGH APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior | Feb 16, 2023 | 8.1 | 25 | NO | NO |
CVE-2026-1497HIGH Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:
an admin that intend | Mar 11, 2026 | 7.2 | 24 | NO | NO |
CVE-2026-1471MEDIUM Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authen | Mar 11, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-1337MEDIUM Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treat | Feb 6, 2026 | 5.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neo4j.
Media articles that mention a CVE ID that affects a product developed by Neo4j — matched by CVE ID, not by vendor name.