VulnSea

mongoid vulnerabilities

CVEs whose affected-version data names the mongoid package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-93764Medium· 6.5
1w ago

Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema

Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable…

▾ Sunlitmongodb · mongoidEPSS 0.15%via NVD
CVE-2026-93763Medium· 6.5
1w ago

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any erro…

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any erro…

▾ Sunlitmongodb · mongoidEPSS 0.15%via NVD
CVE-2026-93762Critical· 9.8
1w ago

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain un…

▾ Midnightmongodb · mongoidEPSS 0.57%via NVD
CVE-2026-93761High· 7.5
1w ago

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications …

▾ Twilightmongodb · mongoidEPSS 0.46%via NVD
CVE-2026-93760High· 8.2
1w ago

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this wa…

▾ Twilightmongodb · mongoidEPSS 0.47%via NVD
CVE-2026-93759High· 8.6
1w ago

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application s…

▾ Twilightmongodb · mongoidEPSS 0.40%via NVD
CVE-2026-93765Critical· 9.1
1w ago

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended inte…

▾ Midnightmongodb · mongoidEPSS 0.51%via NVD
CVE-2026-93758High· 8.1
1w ago

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a requ…

▾ Twilightmongodb · mongoidEPSS 0.36%via NVD
mongoid vulnerabilities (CVEs) · VulnSea