VYPR
Vendor

Mybatis

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2023-25330CriApr 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop…

  • CVE-2022-36594CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.

  • CVE-2020-26945HigOct 10, 2020
    risk 0.00cvss 8.1epss 0.02

    MyBatis before 3.5.6 mishandles deserialization of object streams.