VYPR
Vendor

Mongoid

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2026-93765CriSep 18, 2026
    risk 0.59cvss 9.1epss 0.01

    Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the…

  • CVE-2026-93759HigSep 18, 2026
    risk 0.56cvss 8.6epss 0.00

    Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code…

  • CVE-2026-93760HigSep 18, 2026
    risk 0.53cvss 8.2epss 0.00

    Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may…

  • CVE-2026-93758HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.00

    An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up…

  • CVE-2026-93761HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a…

  • CVE-2026-93764MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party…

  • CVE-2026-2302MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.