Pricing
Case studies
Login
Start trial
mariadb
Maintainer(s)
rusher, +2
Latest version
N/A
Weekly downloads
N/A
npm
LGPL-2.1-or-later
View project
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
1 present
7 patched
0 Mitigation rules
NPM: MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
< 3.2.5
2 hours ago
NPM: MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)
>= 3.2.0, < 3.2.5
2 hours ago
NPM: MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
< 3.2.5
2 hours ago
NPM: MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
>= 3.3.0, < 3.5.4
2 hours ago
NPM: MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
< 3.2.4
28/08/2026
NPM: MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
< 3.2.4
28/08/2026
NPM: MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
< 3.2.4
28/08/2026
NPM: Withdrawn Advisory: mariadb was malware
<= 1.0.2
18/07/2018