sequelizejs records
14 published records for vendor sequelizejs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-790 Improper Filtering of Special Elements1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-10550No exploit | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | Critical9.8 | — | 1.9% | May 31, 2018 |
40Plan | CVE-2016-10554No exploit | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | Critical9.8 | — | 1.9% | May 31, 2018 |
39Monitor | CVE-2019-10752No exploit | Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escapsequelizejs · sequelize · CWE-89 | Critical9.8 | — | 1.5% | Oct 17, 2019 |
39Monitor | CVE-2023-25813Proof of concept | SQL Injection via replacements in sequelizesequelizejs · sequelize · CWE-89 | Critical9.8 | — | 1.4% | Feb 22, 2023 |
39Monitor | CVE-2019-10748No exploit | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped sequelizejs · sequelize · CWE-89 | Critical9.8 | — | 1.3% | Oct 29, 2019 |
39Monitor | CVE-2016-10553No exploit | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | Critical9.8 | — | 1.3% | May 31, 2018 |
39Monitor | CVE-2019-10749No exploit | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Posequelizejs · sequelize · CWE-89 | Critical9.8 | — | 1.2% | Oct 29, 2019 |
39Monitor | CVE-2023-22578No exploit | Sequalize - Default support for “raw attributes” when using parenthesessequelizejs · sequelize · CWE-790 | Critical9.8 | — | 0.8% | Feb 16, 2023 |
35Monitor | CVE-2023-22579No exploit | Sequalize - Unsafe fall-through in getWhereConditionssequelizejs · sequelize · CWE-843 | High8.8 | — | 0.8% | Feb 16, 2023 |
31Monitor | CVE-2019-11069No exploit | Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.sequelizejs · sequelize · CWE-20 | High7.5 | — | 1.8% | Apr 10, 2019 |
30Monitor | CVE-2016-10556No exploit | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | High7.5 | — | 1.3% | May 29, 2018 |
30Monitor | CVE-2023-22580No exploit | Sequalize - Bad query filtering leading to SQL errorssequelizejs · sequelize · CWE-200 | High7.5 | — | 0.6% | Feb 16, 2023 |
30Monitor | CVE-2026-30951Proof of concept | Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Typesequelizejs · sequelize · CWE-89 | High7.5 | — | 0.5% | Mar 10, 2026 |
28Monitor | CVE-2023-6293No exploit | Prototype Pollution in robinbuschmann/sequelize-typescriptsequelizejs · sequelize-typescript · CWE-1321 | High7.1 | — | 0.6% | Nov 24, 2023 |
- CVE-2016-1055040Plan
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
CriticalCVSS 9.8No exploitEPSS 2%sequelizejs · sequelizeMay 31, 2018
- CVE-2016-1055440Plan
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
CriticalCVSS 9.8No exploitEPSS 2%sequelizejs · sequelizeMay 31, 2018
- CVE-2019-1075239Monitor
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escap
CriticalCVSS 9.8No exploitEPSS 1%sequelizejs · sequelizeOct 17, 2019
- CVE-2023-2581339Monitor
SQL Injection via replacements in sequelize
CriticalCVSS 9.8Proof of conceptEPSS 1%sequelizejs · sequelizeFeb 22, 2023
- CVE-2019-1074839Monitor
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped
CriticalCVSS 9.8No exploitEPSS 1%sequelizejs · sequelizeOct 29, 2019
- CVE-2016-1055339Monitor
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
CriticalCVSS 9.8No exploitEPSS 1%sequelizejs · sequelizeMay 31, 2018
- CVE-2019-1074939Monitor
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Po
CriticalCVSS 9.8No exploitEPSS 1%sequelizejs · sequelizeOct 29, 2019
- CVE-2023-2257839Monitor
Sequalize - Default support for “raw attributes” when using parentheses
CriticalCVSS 9.8No exploitEPSS 1%sequelizejs · sequelizeFeb 16, 2023
- CVE-2023-2257935Monitor
Sequalize - Unsafe fall-through in getWhereConditions
HighCVSS 8.8No exploitEPSS 1%sequelizejs · sequelizeFeb 16, 2023
- CVE-2019-1106931Monitor
Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.
HighCVSS 7.5No exploitEPSS 2%sequelizejs · sequelizeApr 10, 2019
- CVE-2016-1055630Monitor
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
HighCVSS 7.5No exploitEPSS 1%sequelizejs · sequelizeMay 29, 2018
- CVE-2023-2258030Monitor
Sequalize - Bad query filtering leading to SQL errors
HighCVSS 7.5No exploitEPSS 1%sequelizejs · sequelizeFeb 16, 2023
- CVE-2026-3095130Monitor
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
HighCVSS 7.5Proof of conceptEPSS 0%sequelizejs · sequelizeMar 10, 2026
- CVE-2023-629328Monitor
Prototype Pollution in robinbuschmann/sequelize-typescript
HighCVSS 7.1No exploitEPSS 1%sequelizejs · sequelize-typescriptNov 24, 2023