Known vulnerabilities in Express

Vendor: Express.js
Software: Express
Software CPE: cpe:2.3:a:expressjs:express:*:*:*:*:*:*:*:*
Total vulnerabilities: 4
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Express Express is affected by 4 known vulnerabilities: 4 medium Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118878 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2024-51999
CWE-1321 Medium
No
No
4.22.0, 5.1.0 01.12.2025 SB2025120158
#VU97209 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-43796
CWE-79 Medium
No
No
4.20.0, 5.0.0 12.09.2024 SB2024091250
SB2024091251
SB2024091252
and 52 more
#VU88532 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-29041
CWE-601 Medium
No
No
4.19.2, 5.0.0 beta.3 15.04.2024 SB2024041530
SB2024041532
SB2024042918
and 44 more
#VU69675 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-24999
CWE-94 Medium
Available
No
4.17.3 29.11.2022 SB2022112910
SB2022112911
SB2022112943
and 49 more