Spring Data module for JPA repositories.
88%
Total Score
100
63
80
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-560146 New spring-data-jpa is vulnerable to SQL Injection in versions 3.0.0 - 4.0.6 and 4.1.0 - 4.1.0. | 3.0.0 - 4.0.64.1.0 - 4.1.0 | Medium |
CVE-2016-6652 org.springframework.data:spring-data-jpa is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 1.9.6 and 1.10.0 - 1.10.4. | 0.0.0 - 1.9.61.10.0 - 1.10.4 | Medium |
CVE-2019-3802 org.springframework.data:spring-data-jpa is vulnerable to Improper Neutralization of Wildcards or Matching Symbols in versions 0.0.0 - 1.11.22, 2.1.0 - 2.1.8 and 2.0.0 - 2.0.14. | 0.0.0 - 1.11.222.0.0 - 2.0.142.1.0 - 2.1.8 | Medium |
CVE-2019-3797 org.springframework.data:spring-data-jpa is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 1.11.20, 2.0.0 - 2.0.14 and 2.1.0 - 2.1.6. | 0.0.0 - 1.11.202.0.0 - 2.0.142.1.0 - 2.1.6 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
${project.groupId}:spring-data-commons Version 4.2.0-M1 | — | — |
org.springframework:spring-orm Version * | — | — |
org.springframework:spring-context Version * | — | — |
org.springframework:spring-aop Version * | — | — |
org.aspectj:aspectjrt Version 1.9.25.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant