Known Vulnerabilities for Sequelize by Sequelizejs
Listed below are 10 of the newest known vulnerabilities associated with "Sequelize" by "Sequelizejs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-52887 json | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0... | Not Provided | 2026-07-15 | 2026-07-20 |
| CVE-2026-30951 json | Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause p... | Not Provided | 2026-03-10 | 2026-07-15 |
| CVE-2023-25813 json | Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Paramete... | 9.8 - CRITICAL | 2023-02-22 | 2023-03-03 |
| CVE-2023-22580 json | Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure. | 7.5 - HIGH | 2023-02-16 | 2023-04-28 |
| CVE-2023-22579 json | Due to improper parameter filtering in the sequalize js library, can a attacker peform injection. | 8.8 - HIGH | 2023-02-16 | 2023-04-28 |
| CVE-2023-22578 json | Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections. | 9.8 - CRITICAL | 2023-02-16 | 2023-03-03 |
| CVE-2019-11069 json | Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used. | 7.5 - HIGH | 2019-04-10 | 2023-11-17 |
| CVE-2019-10752 json | Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper fun... | 9.8 - CRITICAL | 2019-10-17 | 2023-11-07 |
| CVE-2019-10749 json | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sani... | 9.8 - CRITICAL | 2019-10-29 | 2019-10-31 |
| CVE-2019-10748 json | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being pr... | 9.8 - CRITICAL | 2019-10-29 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sequelizejs | Sequelize | 6.0.0 | |||
| Application | Sequelizejs | Sequelize | 6.0.0 | |||
| Application | Sequelizejs | Sequelize | 6.0.0 | |||
| Application | Sequelizejs | Sequelize | 6.0.0 | |||
| Application | Sequelizejs | Sequelize | 5.9.5 | |||
| Application | Sequelizejs | Sequelize | 5.9.4 | |||
| Application | Sequelizejs | Sequelize | 5.9.3 | |||
| Application | Sequelizejs | Sequelize | 5.9.2 | |||
| Application | Sequelizejs | Sequelize | 5.9.1 | |||
| Application | Sequelizejs | Sequelize | 5.9.0 | |||
| Application | Sequelizejs | Sequelize | 5.8.9 | |||
| Application | Sequelizejs | Sequelize | 5.8.8 | |||
| Application | Sequelizejs | Sequelize | 5.8.7 | |||
| Application | Sequelizejs | Sequelize | 5.8.6 | |||
| Application | Sequelizejs | Sequelize | 5.8.5 | |||
| Application | Sequelizejs | Sequelize | 5.8.4 | |||
| Application | Sequelizejs | Sequelize | 5.8.3 | |||
| Application | Sequelizejs | Sequelize | 5.8.2 | |||
| Application | Sequelizejs | Sequelize | 5.8.12 | |||
| Application | Sequelizejs | Sequelize | 5.8.11 |