Sequelizejs / Sequelize
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-30951 | Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type | HIGH | 7.5 | Mar 10, 2026 |
| CVE-2023-25813 | SQL Injection via replacements in sequelize | CRITICAL | 10.0 | Feb 22, 2023 |
| CVE-2023-22579 | Sequalize - Unsafe fall-through in getWhereConditions | CRITICAL | 9.9 | Feb 16, 2023 |
| CVE-2023-22578 | Sequalize - Default support for “raw attributes” when using parentheses | CRITICAL | 10.0 | Feb 16, 2023 |
| CVE-2023-22580 | Sequalize - Bad query filtering leading to SQL errors | HIGH | 7.5 | Feb 16, 2023 |
| CVE-2019-10749 | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect. | CRITICAL | 9.8 | Oct 29, 2019 |
| CVE-2019-10748 | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/Maria… | CRITICAL | 9.8 | Oct 28, 2019 |
| CVE-2019-10752 | Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly… | CRITICAL | 9.8 | Oct 17, 2019 |
| CVE-2019-11069 | Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used. | HIGH | 7.5 | Apr 10, 2019 |
| CVE-2016-10554 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for… | CRITICAL | 9.8 | May 31, 2018 |
| CVE-2016-10553 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for… | CRITICAL | 9.8 | May 31, 2018 |
| CVE-2016-10550 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for… | CRITICAL | 9.8 | May 31, 2018 |
| CVE-2016-10556 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for… | HIGH | 7.5 | May 29, 2018 |
Showing 1 to 13 of 13 CVEs