Releases117
Frequency2 weeks 3 days
Last Release
Stars39.8K
The fantastic ORM library for Golang, aims to be developer friendly

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm