Vulnerabilities > Balderdash

DATE CVE VULNERABILITY TITLE RISK
2018-05-29 CVE-2016-10551 SQL Injection vulnerability in Balderdash Waterline-Sequel 0.5.0
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code.
network
low complexity
balderdash CWE-89
critical
9.8