Mongoose

WordPress plugin · mongoose · WordPress.org ↗
0
Critical
1
High
2
Known total
2
Unfixed
Running Mongoose on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.5
Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
CVE.org
< 6.13.9; >= 7.0.0, <= 7.8.8; >= 8.0.0, <= 8.22.0; >= 9.0.0, <= 9.1.5 unfixed CVE-2026-42334 May 14, 2026
MEDIUM
CVSS 6.5
Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
CVE.org
< 6.13.10; >= 7.0.0, < 7.8.10; >= 8.0.0, < 8.24.1; >= 9.0.0, < 9.7.2 unfixed CVE-2026-73562 Aug 13, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.