Known Vulnerabilities for products from Sequelizejs
Listed below are 14 of the newest known vulnerabilities associated with the vendor "Sequelizejs".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-30951 json | Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause p... | Not Provided | 2026-03-10 | 2026-07-15 |
| CVE-2023-25813 json | Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Paramete... | 9.8 - CRITICAL | 2023-02-22 | 2023-03-03 |
| CVE-2023-22580 json | Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure. | 7.5 - HIGH | 2023-02-16 | 2023-04-28 |
| CVE-2023-22579 json | Due to improper parameter filtering in the sequalize js library, can a attacker peform injection. | 8.8 - HIGH | 2023-02-16 | 2023-04-28 |
| CVE-2023-22578 json | Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections. | 9.8 - CRITICAL | 2023-02-16 | 2023-03-03 |
| CVE-2023-6293 json | Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections. | 7.1 - HIGH | 2023-11-24 | 2023-11-30 |
| CVE-2019-11069 json | Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used. | 7.5 - HIGH | 2019-04-10 | 2023-11-17 |
| CVE-2019-10752 json | Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper fun... | 9.8 - CRITICAL | 2019-10-17 | 2023-11-07 |
| CVE-2019-10749 json | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sani... | 9.8 - CRITICAL | 2019-10-29 | 2019-10-31 |
| CVE-2019-10748 json | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being pr... | 9.8 - CRITICAL | 2019-10-29 | 2023-11-07 |
| CVE-2016-10556 json | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microso... | 7.5 - HIGH | 2018-05-29 | 2019-10-09 |
| CVE-2016-10554 json | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microso... | 9.8 - CRITICAL | 2018-05-31 | 2019-10-09 |
| CVE-2016-10553 json | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microso... | 9.8 - CRITICAL | 2018-05-31 | 2019-10-09 |
| CVE-2016-10550 json | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microso... | 9.8 - CRITICAL | 2018-05-31 | 2019-10-09 |
Known software with vulnerabilities from Sequelizejs
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Sequelizejs | Sequelize | 0.1.0 |