Tag
high
advisory
MikroORM SQL Injection Vulnerability
2 rules 1 TTPMikroORM is vulnerable to SQL injection due to improper escaping in identifier-quoting and JSON-path emitters, enabling attackers to inject arbitrary SQL via manipulated strings passed to public ORM APIs, potentially leading to data leaks, modification, and privilege escalation.
@mikro-orm/sql +1
sql-injection
orm
mikroorm
2r
1t
high
advisory
Drizzle ORM SQL Injection Vulnerability (CVE-2026-39356)
2 rules 5 TTPs 1 CVEDrizzle ORM versions before 0.45.2 and 1.0.0-beta.20 are vulnerable to SQL injection due to improper escaping of SQL identifiers, allowing attackers to inject malicious SQL code through manipulated input leading to potential data breaches.
sql-injection
drizzle-orm
cve-2026-39356
typescript
orm
2r
5t
1c