Piccolo ORM is a lightweight Python object-relational mapping library with a narrow but strategically positioned footprint in Python web application development; its exposure centers on the core library itself. Known weakness patterns in this category of lightweight ORMs typically involve SQL query construction and parameter handling, areas where implementation choices can affect downstream application security. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Piccolo Orm over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47128CRITICAL Piccolo is an object-relational mapping and query builder which supports asyncio. Prior to version 1.1.1, the handling of named transaction `savepoints` in all database implementat | Nov 10, 2023 | 9.1 | 28 | NO | NO |
CVE-2023-41885MEDIUM Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such | Sep 12, 2023 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Piccolo Orm.
Media articles that mention a CVE ID that affects a product developed by Piccolo Orm — matched by CVE ID, not by vendor name.