CVE Tools

MariaDB

424 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for MariaDB, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

MariaDB CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
MariaDB CVEs per month
MonthCVEs
2024-103
2024-110
2024-120
2025-010
2025-020
2025-034
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-032
2026-041
2026-050
2026-069
2026-070
2026-080
2026-090

Severity

How the 424 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical92%
  • High7317%
  • Medium29369%
  • Low4912%

Latest CVEs

The 15 most recently published vulnerabilities affecting MariaDB.

  1. CVE-2026-48165MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side8.0
  2. CVE-2026-48163MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)8.0
  3. CVE-2026-44173MariaDB: FILE privilege was not checked for subqueries in the FROM clause5.0
  4. CVE-2026-44172MariaDB: mysql_real_escape_string() incorrectly handled big59.1
  5. CVE-2026-44171MariaDB: path traversal in mbstream6.3
  6. CVE-2026-44169MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions4.3
  7. CVE-2026-44168MariaDB: wsrep SST unsafe parameter handling on the donor side8.0
  8. CVE-2026-44170MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL9.8
  9. CVE-2026-49261MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`10.0
  10. CVE-2026-35549An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user...6.5
  11. CVE-2026-32710Heap-based Buffer Overflow in MariaDB8.5
  12. CVE-2026-3494MariaDB Server Audit Plugin Comment Handling Bypass4.3
  13. CVE-2025-13699MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability7.0
  14. CVE-2025-30722Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit ...5.3
  15. CVE-2023-52968MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_de...4.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store