Vulnerabilities
Vulnerable Software
Mongoosejs:  >> Mongoose  >> 5.13.20  Security Vulnerabilities
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
CVSS Score
9.0
EPSS Score
0.624
Published
2025-01-15
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
CVSS Score
9.1
EPSS Score
0.644
Published
2024-12-02


Contact Us

Shodan ® - All rights reserved