Sequelize

Vendor:

First CVE: May 29, 2018 · Active for 8 years

13
Total CVEs
More Total CVEs than 91% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
9.0
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sequelize over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2018
8 years ago
Most Recent CVE
Mar 10, 2026
136 days ago

CVE Severity & Scoring

Sequelize13 CVEs
All CVEs352,294 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None12 (92.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.
Oct 29, 20199.831NONO
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub
Oct 17, 20199.831NONO
Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
Feb 16, 20239.830NONO
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
Oct 29, 20199.830NONO
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input
May 31, 20189.830NONO
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before versi
May 31, 20189.828NONO
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
Feb 16, 20238.827NONO
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pu
May 31, 20189.827NONO
Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON pat
Mar 10, 20267.526NONO
Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.
Apr 10, 20197.525NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Sequelize

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0.038.70.7%00
1.7.019.81.9%00