VulnSea

laravel_mongodb_php vulnerabilities

CVEs whose affected-version data names the laravel_mongodb_php package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-88027High· 7.1
1w ago

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

TwilightMongoDB · Laravel MongoDB (PHP)EPSS 0.23%via NVD
CVE-2026-88028Medium· 6.5
1w ago

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

SunlitMongoDB · Laravel MongoDB (PHP)EPSS 0.24%via NVD
CVE-2026-88022High· 7.7
1w ago

Unauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for Laravel

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This…

TwilightMongoDB · Laravel MongoDB (PHP)EPSS 0.30%via CVEORG
laravel_mongodb_php vulnerabilities (CVEs) · VulnSea