Mongo-Express Project
5 known vulnerabilities
Top Products
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: h
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CS
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this m
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
Frequently Asked Questions
How many CVEs affect Mongo-Express Project?
Mongo-Express Project has 5 CVE records in our database, including 2 critical and 1 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mongo-Express Project vulnerabilities?
Mongo-Express Project has 2 critical severity (CVSS 9.0+) and 1 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mongo-Express Project vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mongo-Express Project products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mongo-Express Project Vulnerabilities
CyberStrike scans your infrastructure for Mongo-Express Project vulnerabilities and provides real-time remediation guidance.
Get Started