Known vulnerabilities in MongoDB driver for PHP
Vendor:
MongoDB, Inc.
Software:
MongoDB driver for PHP
Software CPE:
cpe:2.3:a:mongodb:mongodb_driver_for_php:*:*:*:*:*:php:*:*
Website:
https://www.mongodb.com/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
2.3.3
2.3.2
2.3.1
2.3.0
2.2.1
2.2.0
2.1.8
2.1.7
1.21.5
1.21.4
2.1.4
2.1.3
1.21.2
2.1.2
2.1.1
1.21.1
2.1.0
2.0.0
1.21.0
1.20.1
1.20.0
1.19.4
1.19.3
1.19.2
1.19.1
1.19.0
1.18.1
1.18.0
1.17.3
1.17.2
1.17.1
1.17.0
1.16.2
1.16.1
1.16.0
1.15.3
1.15.2
1.15.1
1.15.0
1.14.2
1.14.1
1.14.0
1.13.0
1.12.1
1.12.0
1.11.1
1.11.0
1.10.0
1.9.2
1.9.1
1.9.0
1.8.2
1.8.1
1.8.0
1.7.5
1.7.4
1.7.3
1.7.2
1.7.1
1.7.0
1.6.1
1.6.0
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.2.11
1.2.10
1.2.9
1.2.8
1.2.7
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.1.10
1.1.9
1.1.8
1.1.7
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.1
1.0.0
0.6.3
0.6.2
0.6.1
0.6.0
0.5.1
0.5.0
0.4.1
0.4.0
0.3.1
0.3.0
0.2.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU119959 - Expired pointer dereference CVE-2025-12119 |
CWE-825 | Medium | 1.21.2 | 15.12.2025 |
SB2025121521 SB2025121526 SB2025121527 and 3 more |
||
| #VU111878 - Improper Access Control CVE-2024-7553 |
CWE-284 | Medium | 1.18.1 | 24.06.2025 |
SB2025062440 SB2025062503 SB2025100707 |