cbcvebase.

Mariadb Server vulnerabilities

10 known vulnerabilities affecting mariadb/server.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-32710P2CRITICALCVSS 9.9v>= 11.4.1, < 11.4.10v>= 11.8.1, < 11.8.6+1 more2026-03-20
CVE-2026-32710 [CRITICAL] CWE-122 CVE-2026-32710: MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaD MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout
nvd
CVE-2026-44170P2CRITICALCVSS 9.8v>= 10.6.1, < 10.6.26v>= 10.11.1, < 10.11.17+3 more2026-06-12
CVE-2026-44170 [CRITICAL] CWE-78 CVE-2026-44170: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitiz
nvd
CVE-2026-49261P2CRITICALCVSS 9.8v>= 10.6.1, < 10.6.27v>= 10.11.1, < 10.11.18+3 more2026-06-11
CVE-2026-49261 [CRITICAL] CWE-78 CVE-2026-49261: MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11 MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a
nvd
CVE-2026-44172P3CRITICALCVSS 9.1v= 3.3.18v= 3.4.82026-06-12
CVE-2026-44172 [CRITICAL] CWE-89 CVE-2026-44172: MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an appli MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was suppos
nvd
CVE-2026-48163P3HIGHCVSS 7.2v>= 10.6.1, < 10.6.27v>= 10.11.1, < 10.11.18+3 more2026-06-12
CVE-2026-48163 [HIGH] CWE-78 CVE-2026-48163: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allo
nvd
CVE-2026-44168P3HIGHCVSS 8.0v>= 10.6.1, < 10.6.26v>= 10.11.1, < 10.11.17+3 more2026-06-12
CVE-2026-44168 [HIGH] CWE-78 CVE-2026-44168: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allo
nvd
CVE-2026-48165P3HIGHCVSS 7.2v>= 10.6.1, < 10.6.27v>= 10.11.1, < 10.11.18+3 more2026-06-12
CVE-2026-48165 [HIGH] CWE-78 CVE-2026-48165: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mar
nvd
CVE-2026-44171P3HIGHCVSS 7.8v>= 10.6.1, < 10.6.26v>= 10.11.1, < 10.11.17+3 more2026-06-12
CVE-2026-44171 [HIGH] CWE-22 CVE-2026-44171: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have
nvd
CVE-2026-44173P4MEDIUMCVSS 5.3v>= 10.6.1, < 10.6.26v>= 10.11.1, < 10.11.17+3 more2026-06-12
CVE-2026-44173 [MEDIUM] CWE-863 CVE-2026-44173: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This i
nvd
CVE-2026-44169P4MEDIUMCVSS 4.3v>= 11.4.1, < 11.4.11v>= 11.8.1, < 11.8.7+1 more2026-06-12
CVE-2026-44169 [MEDIUM] CWE-863 CVE-2026-44169: MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11 MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.
nvd
Mariadb Server vulnerabilities | cvebase