Tortoise ORM is a Python-based object-relational mapping library used for asynchronous database interaction, with a narrow product scope centered on the ORM framework itself. The observed vulnerability signal reflects input-handling risks in SQL query construction, specifically SQL injection conditions that can arise when user-supplied data is inadequately sanitized before database operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tortoise Orm Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11010HIGH In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & | Apr 20, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tortoise Orm Project.
Media articles that mention a CVE ID that affects a product developed by Tortoise Orm Project — matched by CVE ID, not by vendor name.