Grocerycrud is a code-generation library for building administrative interfaces and CRUD operations on relational databases, with a narrow product footprint centered on the Grocery CRUD framework. The primary recurring exposure involves SQL injection weaknesses arising from insufficient neutralization of special characters in database queries, typical of frameworks that dynamize SQL construction. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Grocerycrud over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-47811CRITICAL Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL | Jan 16, 2026 | 9.1 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Grocerycrud.
Media articles that mention a CVE ID that affects a product developed by Grocerycrud — matched by CVE ID, not by vendor name.