CVE Tools

Mongoose

69 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mongoose, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Mongoose CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mongoose CVEs per month
MonthCVEs
2024-100
2024-1110
2024-121
2025-011
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-091
2025-100
2025-111
2025-120
2026-010
2026-023
2026-030
2026-045
2026-051
2026-060
2026-072
2026-089
2026-090

Severity

How the 69 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2538%
  • High1523%
  • Medium2132%
  • Low46%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mongoose.

  1. CVE-2026-73253Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching—
  2. CVE-2026-73255Mongoose: Path traversal in SSI #include directives enables arbitrary file read6.5
  3. CVE-2026-73259Mongoose: Reflected XSS via decoded URI in directory listing render5.4
  4. CVE-2026-73256Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE9.1
  5. CVE-2026-73254Mongoose: Stored XSS via unescaped filenames in directory listing5.4
  6. CVE-2026-73258Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart6.5
  7. CVE-2026-73251Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification—
  8. CVE-2026-73257Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling9.1
  9. CVE-2026-73562Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)6.5
  10. GHSA-664h-wqgq-64gwMongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)—
  11. CVE-2026-11404Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing7.5
  12. CVE-2026-42334Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection7.5
  13. CVE-2026-6986Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification3.7
  14. CVE-2026-6985Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop5.3
  15. CVE-2026-5246Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization5.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store