Known vulnerabilities in morgan
Vendor:
Express.js
Software:
morgan
Software CPE:
cpe:2.3:a:expressjs:morgan:*:*:*:*:*:*:*:*
Website:
https://expressjs.com/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.9
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146052 - Improper Output Neutralization for Logs CVE-2026-15603 |
CWE-117 | Medium | 1.12.0 | 28.08.2026 |
SB2026082834 |
||
| #VU146051 - Improper Output Neutralization for Logs CVE-2026-5078 |
CWE-117 | Medium | 1.11.0 | 28.08.2026 |
SB2026082833 |