Baomidou develops MyBatis-Plus, a Java-based ORM framework that extends the popular MyBatis persistence library for database access in enterprise applications. The observed vulnerability signal centers on SQL injection weaknesses arising from improper neutralization of user input in database query construction, a class of flaw that recurs in data-access layers when input validation and parameterization are incomplete.
The number and severity of CVEs published that impact products developed by Baomidou over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25517CRITICAL MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that t | Mar 22, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baomidou.
Media articles that mention a CVE ID that affects a product developed by Baomidou — matched by CVE ID, not by vendor name.