« Back to list

Mysql

Mysql: vulnerabilities and CVEs

Mysql has 114 published vulnerabilities, 18 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs114
Last 12 months18
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-90997High (7.4)0.40%—Sep 17, 2026
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay…
CVE-2026-55650Medium (4.4)0.19%—Sep 15, 2026
Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget…
CVE-2026-19475Medium (6.5)0.40%—Sep 2, 2026
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject.…
CVE-2026-55859Medium (5.9)0.49%—Aug 28, 2026
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character…
CVE-2026-55857Medium (5.9)0.39%—Aug 28, 2026
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account…
CVE-2026-55855Medium (6.5)0.47%—Aug 28, 2026
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when…
CVE-2026-59335High (8.7)0.53%—Aug 25, 2026
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority…
CVE-2026-56704Medium (5.3)0.34%—Aug 25, 2026
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings…
CVE-2026-73300Critical (9.6)0.56%—Aug 12, 2026
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query.…
CVE-2026-72607High (7.1)0.45%—Aug 11, 2026
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary database contents by storing a SQL…
CVE-2026-72881Medium (6.4)0.67%—Aug 10, 2026
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts…
CVE-2026-72869Critical (9.9)0.65%—Aug 10, 2026
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in…
CVE-2026-18617High (8.8)0.73%—Aug 10, 2026
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into…
CVE-2026-62845Medium (4.7)0.32%—Jul 30, 2026
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema…
CVE-2026-42201Low (3.3)0.31%—Jul 7, 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password,…
CVE-2026-53949Medium (5.3)0.36%—Jun 24, 2026
Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute…
CVE-2026-50267Medium (4.7)0.08%—Jun 17, 2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service…
CVE-2026-44047High (8.8)0.51%—May 21, 2026
An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service.
CVE-2025-45065Critical (9.8)0.41%—Jul 7, 2025
employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.
CVE-2025-24337High (8.4)0.21%—Jan 20, 2025
WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
CVE-2024-32879Medium (4.9)0.58%—Apr 24, 2024
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not…
CVE-2017-15945High (7.8)0.37%—Oct 27, 2017
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees,…
CVE-2015-2575Medium (4.9)3.6%—Apr 16, 2015
Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.
CVE-2013-1492High (7.5)2.8%—Mar 28, 2013
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulnerability than CVE-2012-0553.
CVE-2012-0553High (7.5)2.6%—Mar 28, 2013
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulnerability than CVE-2013-1492.
CVE-2012-0882High (7.5)5.3%—Dec 21, 2012
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as…
CVE-2012-2749Medium (4)1.9%—Aug 17, 2012
MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
CVE-2012-2102Low (3.5)2.1%—Aug 17, 2012
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
CVE-2009-5026Medium (6.8)7.8%—Aug 17, 2012
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to…
CVE-2012-1696Medium (4)1.9%—May 3, 2012
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services4
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter1
  4. T1078.001 Default Accounts1
  5. T1078.004 Cloud Accounts1
  6. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Mysql