Every CVE whose affected-product data names Mongodb Mongoid, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (8)
CVE-2026-93762 — CVSS 9.8 (critical): Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally…
CVE-2026-93765 — CVSS 9.1 (critical): Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are…
CVE-2026-93759 — CVSS 8.6 (high): Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a…
CVE-2026-93760 — CVSS 8.2 (high): Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its…
CVE-2026-93758 — CVSS 8.1 (high): An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic…
CVE-2026-93761 — CVSS 7.5 (high): An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an…
CVE-2026-93763 — CVSS 6.5 (medium): A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application…
CVE-2026-93764 — CVSS 6.5 (medium): Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema…