Hibernate is an object-relational mapping and validation framework widely embedded in Java applications, with its vulnerability footprint concentrated in the core ORM and validator components. The recurring vulnerability classes reflect the framework's role in data persistence and input handling: SQL injection flaws in query construction and cross-site scripting risks in validation and rendering contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hibernate over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25638HIGH A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals wh | Dec 2, 2020 | 7.4 | 25 | NO | NO |
CVE-2019-14900MEDIUM A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals w | Jul 6, 2020 | 6.5 | 23 | NO | NO |
CVE-2023-1932MEDIUM A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omittin | Nov 7, 2024 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hibernate.
Media articles that mention a CVE ID that affects a product developed by Hibernate — matched by CVE ID, not by vendor name.