Arangodb

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-25367

    ArangoDB Community Edition 3.4.2-1 XSS via aardvark admin interface

    Last Modified: Jul 15, 2026
    Published: Feb 15, 2026

    CVE-2021-25939

    ArangoDB - Blind SSRF when Downloading Foxx Service from URL

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2022

    CVE-2021-25940

    ArangoDB - Insufficient Session Expiration after Password Change

    Last Modified: Apr 30, 2025
    Published: Nov 16, 2021

    CVE-2021-25938

    In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.

    Last Modified: Nov 21, 2024
    Published: May 24, 2021
    Items Per Page