Data-Mapper ORM for TypeScript and ES2023+. Supports MySQL/MariaDB, PostgreSQL, MS SQL Server, Oracle, SAP HANA, SQLite, MongoDB databases.
87%
Total Score
62
100
100
100
73
| Title | Versions | Severity |
|---|---|---|
CVE-2025-60542 typeorm is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 0.3.26. | 0.0.0 - 0.3.26 | Medium |
AIKIDO-2025-10205 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. typeorm is vulnerable to Improper String Escaping in versions 0.3.0 - 0.3.21. | 0.3.0 - 0.3.21 | High |
CVE-2022-33171 typeorm is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 0.3.0. | 0.0.0 - 0.3.0 | Critical |
CVE-2020-8158 typeorm is vulnerable to Modification of Assumed-Immutable Data (MAID) in versions 0.0.0 - 0.2.25. | 0.0.0 - 0.2.25 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
ansis Version ^4.2.0 | — | — |
dayjs Version ^1.11.20 | — | — |
debug Version ^4.4.3 | — | — |
tslib Version ^2.8.1 | — | — |
yargs Version ^18.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant