Querymen Project maintains a focused query-manipulation library that, despite narrow product scope, carries embedded risk through widespread downstream integration in applications that consume or transform user-supplied query data. The durable vulnerability signal centers on prototype pollution—a class of object-attribute manipulation flaws—that arises in the library's handling of object construction and property inheritance. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Querymen Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25871HIGH All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitiz | Jun 17, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-7600MEDIUM querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. T | Mar 12, 2020 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Querymen Project.
Media articles that mention a CVE ID that affects a product developed by Querymen Project — matched by CVE ID, not by vendor name.