sqlalchemy records
5 published records for vendor sqlalchemy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-7164No exploit | SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.sqlalchemy · sqlalchemy · CWE-89 | Critical9.8 | — | 3.5% | Feb 19, 2019 |
32Monitor | CVE-2019-7548No exploit | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.sqlalchemy · sqlalchemy · CWE-89 | High7.8 | — | 1.8% | Feb 6, 2019 |
31Monitor | CVE-2012-0805No exploit | Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL cosqlalchemy · sqlalchemy · CWE-89 | High7.5 | — | 2.9% | Jun 5, 2012 |
31Monitor | CVE-2022-40023No exploit | Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse.sqlalchemy · mako · CWE-1333 | High7.5 | — | 2.2% | Sep 7, 2022 |
30Monitor | CVE-2026-41205No exploit | Mako: Path traversal via double-slash URI prefix in TemplateLookupsqlalchemy · mako · CWE-22 | High7.7 | — | 0.5% | Apr 23, 2026 |
- CVE-2019-716440Plan
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
CriticalCVSS 9.8No exploitEPSS 4%sqlalchemy · sqlalchemyFeb 19, 2019
- CVE-2019-754832Monitor
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
HighCVSS 7.8No exploitEPSS 2%sqlalchemy · sqlalchemyFeb 6, 2019
- CVE-2012-080531Monitor
Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL co
HighCVSS 7.5No exploitEPSS 3%sqlalchemy · sqlalchemyJun 5, 2012
- CVE-2022-4002331Monitor
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse.
HighCVSS 7.5No exploitEPSS 2%sqlalchemy · makoSep 7, 2022
- CVE-2026-4120530Monitor
Mako: Path traversal via double-slash URI prefix in TemplateLookup
HighCVSS 7.7No exploitEPSS 1%sqlalchemy · makoApr 23, 2026