MySQL, MariaDB and Percona CVEs

Three-year CVE watchlist for MySQL, MariaDB and Percona database servers used in business and hosting environments.

Dedicated CVE watchlist

MySQL, MariaDB and Percona CVEs

Three-year CVE watchlist for MySQL, MariaDB and Percona database servers used in business and hosting environments.

Server administration
CategorySwitch between product-focused CVE watchlists.
Showsorted by operational relevance for DataHouse infrastructure
CVE-2019-25224CVSS 9.8CMS

CVE-2019-25224: wp database backup vulnerability

The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.

Updated: 2026-06-17
CVE-2026-40887CVSS 9.1Database

CVE-2026-40887

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpo...

Updated: 2026-06-17
CVE-2025-34227CVSS 8.6Database

CVE-2025-34227: nagios xi vulnerability

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to th...

Updated: 2026-06-17
CVE-2025-34205CVSS 9.3Web

CVE-2025-34205: virtual appliance application vulnerability

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code present in multiple Docker-hosted PHP instances. A script named /var/www/app...

Updated: 2026-06-17
CVE-2026-49261CVSS 10.0Database

CVE-2026-49261: mariadb vulnerability

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the ...

Updated: 2026-07-15
CVE-2026-41229CVSS 9.1Database

CVE-2026-41229: froxlor vulnerability

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permissio...

Updated: 2026-06-17
CVE-2026-27969CVSS 9.3Linux

CVE-2026-27969: vitess vulnerability

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest ...

Updated: 2026-06-17
CVE-2026-53595CVSS 9.4Web

CVE-2026-53595

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `invite_has...

Updated: 2026-07-21
CVE-2026-29080CVSS 9.4Database

CVE-2026-29080: rucio vulnerability

A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (`GET /dids/<scope>/dids/search`). On Oracle deployments attacker-c...

Updated: 2026-06-17
CVE-2024-21508CVSS 9.8Database

CVE-2024-21508

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

Updated: 2026-06-17
CVE-2023-26785CVSS 9.8Database

CVE-2023-26785: mariadb vulnerability

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

Updated: 2026-06-17
CVE-2026-3960CVSS 9.8Database

CVE-2026-3960: h2o vulnerability

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism, which...

Updated: 2026-06-17
CVE-2026-57517CVSS 9.3Web

CVE-2026-57517

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers...

Updated: 2026-07-02
CVE-2026-54419CVSS 9.3Web

CVE-2026-54419

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The application has no authentication mechanism ...

Updated: 2026-06-22
CVE-2026-44168CVSS 8.0Database

CVE-2026-44168: mariadb vulnerability

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that t...

Updated: 2026-07-15
CVE-2025-34206CVSS 9.3Containers

CVE-2025-34206: virtual appliance application vulnerability

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files su...

Updated: 2026-06-17
CVE-2026-25879CVSS 9.8Database

CVE-2026-25879

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabl...

Updated: 2026-07-21
CVE-2026-55740CVSS 9.3Web

CVE-2026-55740

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated directly into a MySQL qu...

Updated: 2026-06-22
CVE-2026-48188CVSS 9.1Database

CVE-2026-48188: otrs vulnerability

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is conf...

Updated: 2026-07-22
CVE-2026-48773CVSS 9.8Database

CVE-2026-48773

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can decla...

Updated: 2026-06-23
CVE-2026-48241CVSS 9.2Web

CVE-2026-48241

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with ...

Updated: 2026-07-23
CVE-2026-48242CVSS 9.2Web

CVE-2026-48242

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the ...

Updated: 2026-07-23
CVE-2025-10703CVSS 8.6Windows

CVE-2025-10703

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option i...

Updated: 2026-06-17
CVE-2025-10702CVSS 8.6Windows

CVE-2025-10702

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option ...

Updated: 2026-06-17
CVE-2026-48772CVSS 10.0Database

CVE-2026-48772

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY ...

Updated: 2026-06-23
CVE-2023-46127CVSS 5.4Database

CVE-2023-46127: frappe vulnerability

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vu...

Updated: 2026-06-17
CVE-2024-21512CVSS 8.2Database

CVE-2024-21512

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

Updated: 2026-06-17
CVE-2024-10553CVSS 9.8Database

CVE-2024-10553: h2o vulnerability

A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The vulnerability exists in the endpoints POST /99/ImportSQLTable and POST /3/SaveToHiveTa...

Updated: 2026-06-17
CVE-2024-31864CVSS 9.8Web

CVE-2024-31864: zeppelin vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1....

Updated: 2026-06-17
CVE-2024-21511CVSS 9.8Database

CVE-2024-21511

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

Updated: 2026-06-17
CVE-2026-48165CVSS 8.0Database

CVE-2026-48165: mariadb vulnerability

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_a...

Updated: 2026-07-15
CVE-2026-32710CVSS 8.5Database

CVE-2026-32710: mariadb vulnerability

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the cr...

Updated: 2026-06-17
CVE-2026-56287CVSS 8.1Web

CVE-2026-56287: fineract vulnerability

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validat...

Updated: 2026-07-15
CVE-2024-30985CVSS 9.8Web

CVE-2024-30985: client management system vulnerability

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

Updated: 2026-06-17
CVE-2024-30980CVSS 9.8Web

CVE-2024-30980: cyber cafe management system vulnerability

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.

Updated: 2026-06-17
CVE-2026-48163CVSS 8.0Database

CVE-2026-48163: mariadb vulnerability

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that t...

Updated: 2026-07-15
CVE-2024-30990CVSS 9.8Web

CVE-2024-30990: client management system vulnerability

SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.

Updated: 2026-06-17
CVE-2025-3579CVSS 9.3Web

CVE-2025-3579

In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with internal services such a...

Updated: 2026-06-17
CVE-2024-55496CVSS 9.1Web

CVE-2024-55496: bookstore management system vulnerability

A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.

Updated: 2026-06-17
CVE-2026-30778CVSS 7.5Web

CVE-2026-30778: skywalking vulnerability

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue.

Updated: 2026-06-17
CVE-2026-46850CVSS 9.9Database

CVE-2026-46850: mysql shell vulnerability

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise M...

Updated: 2026-06-22
CVE-2026-46860CVSS 9.8Database

CVE-2026-46860: mysql router vulnerability

Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL ...

Updated: 2026-06-18
CVE-2024-30982CVSS 9.8Web

CVE-2024-30982: cyber cafe management system vulnerability

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

Updated: 2026-06-17
CVE-2024-30981CVSS 9.8Web

CVE-2024-30981: cyber cafe management system vulnerability

SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL.

Updated: 2026-06-17
CVE-2025-26701CVSS 10.0Database

CVE-2025-26701

An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-...

Updated: 2026-06-17
CVE-2026-4021CVSS 8.1Web

CVE-2026-4021

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-conf...

Updated: 2026-06-17
CVE-2014-7210CVSS 9.8Database

CVE-2014-7210: pdns vulnerability

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.

Updated: 2026-06-17
CVE-2026-27965CVSS 8.4Linux

CVE-2026-27965: vitess vulnerability

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is late...

Updated: 2026-06-17
CVE-2026-30849CVSS 9.3Database

CVE-2026-30849: mantisbt vulnerability

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parame...

Updated: 2026-06-17
CVE-2025-45065CVSS 9.8Web

CVE-2025-45065

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

Updated: 2026-06-17
CVE-2026-46861CVSS 9.6Database

CVE-2026-46861: mysql ndb cluster vulnerability

Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows low privileged attacker wit...

Updated: 2026-06-18
CVE-2025-67510CVSS 9.4Web

CVE-2025-67510: neuron vulnerability

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the na...

Updated: 2026-06-17
CVE-2026-25212CVSS 9.9Database

CVE-2026-25212: monitoring and management vulnerability

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell comm...

Updated: 2026-06-17
CVE-2025-34201CVSS 8.5Containers

CVE-2025-34201: virtual appliance application vulnerability

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation between instances. A compromise of any single container allows d...

Updated: 2026-06-17
CVE-2026-43873CVSS 7.5Web

CVE-2026-43873

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($global['systemRootPath'] . $global['salt'])) into the HTTP ...

Updated: 2026-06-17
CVE-2026-50267CVSS 4.7Linux

CVE-2026-50267

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include T...

Updated: 2026-06-22
CVE-2024-8929CVSS 5.8Database

CVE-2024-8929: php vulnerability

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of th...

Updated: 2026-06-17
CVE-2023-5157CVSS 7.5Database

CVE-2023-5157: mariadb vulnerability

A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

Updated: 2026-06-17

Security newsletter

Get new CVE alerts before they become an incident

We send selected infrastructure threats in English, with practical notes for DataHouse environments.

  • DataHouse: server administration and secure cloud
  • Hostilla.pl: hosting and mail services
  • SecDNS.pl: free DNS security layer