<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Neo4j</title>
  <link>https://cvedaily.com/pages/tags/neo4j.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/neo4j.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Neo4j</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:53 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-41274 – Flowise is a drag &amp; drop user interface to build a customized large language mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41274</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41274</strong></p>
  <p>Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. Th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-35402 – mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35402</guid>
    <pubDate>Fri, 17 Apr 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-35402</strong></p>
  <p>mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentially allowing unauthorized write operations or server-side request forgery. This issue is fixed in version 0.6.0.</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22743 – Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22743</guid>
    <pubDate>Fri, 27 Mar 2026 06:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22743</strong></p>
  <p>Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited Cypher property accessor (node.`metadata.`) after stripping only double quotes, without escaping emb…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32247 – Graphiti is a framework for building and querying temporal context graphs for AI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32247</guid>
    <pubDate>Thu, 12 Mar 2026 19:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32247</strong></p>
  <p>Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter construction for non-Kuzu backends. Attacker-controlled label values supplied through SearchFilters.node_labels were concatenated directly into Cypher label expressions without validation. In MCP deployments, th…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1524 – An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1524</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1524</strong></p>
  <p>An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:   If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to be authentication-only, then those that are authentication-only will also pro…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1471 – Excessive caching of authentication context in Neo4j Enterprise edition versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1471</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1471</strong></p>
  <p>Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint).  We recommend upgrading to versions 2026.01.4 (or 5.26.22) where the issue is fixed.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1497 – Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1497</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1497</strong></p>
  <p>Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "name". If such database or alias doesn't exist when the command…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1337 – Insufficient escaping of unicode characters in query log in Neo4j Enterprise and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1337</guid>
    <pubDate>Fri, 06 Feb 2026 14:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1337</strong></p>
  <p>Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01.  Proof of concept exploit:  https://github…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1622 – Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1622</guid>
    <pubDate>Wed, 04 Feb 2026 10:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1622</strong></p>
  <p>Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files.   The "obfuscate_literals" option in the query logs does not redact error information, exposing unredacted data in the query log when a customer writes a query that fails. It can allow a user with legitimate a…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-12738 – Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12738</guid>
    <pubDate>Thu, 22 Jan 2026 15:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-12738</strong></p>
  <p>Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database. The vulnerability allows attacker without read access to a property to infer information about its value by trying to enumerate all possible values through observing error messages of SET property. We recommend upgradi…</p>
  <p><strong>CVSS:</strong> 1.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66169 – Cypher Injection vulnerability in Apache Camel camel-neo4j component.

This issu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66169</guid>
    <pubDate>Wed, 14 Jan 2026 12:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66169</strong></p>
  <p>Cypher Injection vulnerability in Apache Camel camel-neo4j component.  This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0  Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11602 – Potential information leak in bolt protocol handshake in Neo4j Enterprise and Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11602</guid>
    <pubDate>Fri, 31 Oct 2025 11:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11602</strong></p>
  <p>Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-226</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10193 – DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10193</guid>
    <pubDate>Thu, 11 Sep 2025 14:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10193</strong></p>
  <p>DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56406 – An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56406</guid>
    <pubDate>Wed, 10 Sep 2025 14:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56406</strong></p>
  <p>An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middle…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34517 – The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34517</guid>
    <pubDate>Tue, 07 May 2024 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34517</strong></p>
  <p>The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-471</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23926 – APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML Exter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23926</guid>
    <pubDate>Thu, 16 Feb 2023 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23926</strong></p>
  <p>APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 and 4.4.0.14 (4.4 branch) in Neo4j graph database. XML External Entity (XXE) injection occurs when the XML parser allows external entities to be resolved. The XML parser used by the apoc.import.graphml…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23532 – APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23532</guid>
    <pubDate>Sat, 14 Jan 2023 01:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23532</strong></p>
  <p>APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A path traversal vulnerability found in the apoc.export.* procedures of apoc plugins in Neo4j Graph database. The issue allows a malicious actor to potentially break out of the expected directory. The vulnerability is such that files could only be created but not overwritten. For…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-37423 – Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37423</guid>
    <pubDate>Fri, 12 Aug 2022 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-37423</strong></p>
  <p>Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-42767 – A directory traversal vulnerability in the apoc plugins in Neo4J Graph database ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-42767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-42767</guid>
    <pubDate>Tue, 01 Mar 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-42767</strong></p>
  <p>A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-34371 – Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34371</guid>
    <pubDate>Thu, 05 Aug 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-34371</strong></p>
  <p>Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies with exploitable gadget chains.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34802 – A failure in resetting the security context in some transaction actions in Neo4j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34802</guid>
    <pubDate>Fri, 30 Jul 2021 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34802</strong></p>
  <p>A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1000820 – neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000820</guid>
    <pubDate>Thu, 20 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1000820</strong></p>
  <p>neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-18389 – Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18389</guid>
    <pubDate>Tue, 16 Oct 2018 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-18389</strong></p>
  <p>Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7259 – Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7259</guid>
    <pubDate>Tue, 29 Apr 2014 14:38:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7259</strong></p>
  <p>Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrated by a request to (1) db/data/ext/GremlinPlugin/graphdb/execute_script or (2) db/manage/server/console/.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7259">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
