Mongo-express Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    2
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-52555

    In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.

    Last Modified: May 13, 2025
    Published: Mar 01, 2024

    CVE-2021-21422

    XSS Vulnerability in mongo-express

    Last Modified: Nov 21, 2024
    Published: Jun 21, 2021

    CVE-2021-23372

    Denial of Service (DoS)

    Last Modified: Nov 21, 2024
    Published: Apr 13, 2021

    CVE-2020-24391

    mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.

    Last Modified: Nov 21, 2024
    Published: Mar 30, 2021

    CVE-2019-10758

    mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

    Last Modified: Oct 27, 2025
    Published: Dec 24, 2019
    Items Per Page