mikro-orm has 3 CVEs on record. 1 was published in the last 90 days. The median CVSS is 9.1 (critical), with 2 rated critical. Most affected products: mikroorm (2), mikro-orm (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Weakness classes
Products
- mikroorm 2
- mikro-orm 1
Worst active — by depth score
CVE-2026-34220Critical· 9.8MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns66CVE-2026-34221Critical· 9.1MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns50CVE-2026-84993Medium· 6.5MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns36
mikro-orm vulnerabilities
CVEs affecting mikro-orm, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-84993Medium· 6.5MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an orderBy clause but does not validate its direction value…
CVE-2026-34221Critical· 9.1MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM w…
CVE-2026-34220Critical· 9.8PoCMikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL q…