Doctrine Project maintains a narrowly focused collection of PHP libraries and database abstraction layers, including its core ORM framework, caching, and annotation-handling components that serve as foundational infrastructure for many PHP applications. The vendor's limited disclosure history centers on this library and middleware scope, with structural risk reflecting the integration points inherent to database abstraction and object-mapping frameworks. Current vulnerability counts, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doctrine Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43608CRITICAL Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL | Dec 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2011-1522HIGH Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote att | May 3, 2011 | 7.5 | 22 | NO | NO |
CVE-2015-5723HIGH Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before | Jun 7, 2016 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doctrine Project.
Media articles that mention a CVE ID that affects a product developed by Doctrine Project — matched by CVE ID, not by vendor name.