Home/Product/neo4j
Product

neo4j

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-1497
< 5.26.22
Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lea
7.2HIGH
CVE-2026-1337
< 2026.01
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to X
5.4MEDIUM
CVE-2024-34517
>= 5.0.0 and < 5.19.0
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has
6.5MEDIUM
CVE-2023-23926
< 5.5.0
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.i
5.9MEDIUM
CVE-2022-23532
< 4.3.0.12
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A path trav
7.1HIGH
CVE-2022-37423
< 4.3.0.7
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories
7.5HIGH
CVE-2021-42767
< 3.5.0.17
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local file
9.1CRITICAL
CVE-2021-34371
<= 3.4.18
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., thro
9.8CRITICAL
CVE-2021-34802
all versions
A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authentica
8.8HIGH
CVE-2018-1000820
all versions
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser
10.0CRITICAL
CVE-2018-18389
>= 3.4.0 and < 3.4.9
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication wit
9.8CRITICAL
CVE-2013-7259
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of a
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin