A security vulnerability has been identified in specific older versions of MariaDB, a widely used open-source database software that powers many websites to store content, user information, and other site data. The flaw only impacts MariaDB versions 3.3.18 and 3.4.8. For sites running these affected versions with the big5 character set enabled, a common safeguard that websites use to filter user-submitted data (such as form entries, search queries, or other user-provided information) fails to work as intended. This creates a risk of SQL injection attacks, where bad actors could send malicious input to access, modify, or delete your site's stored data, or disrupt your website's normal functionality. The team that develops MariaDB has released updated versions 3.3.19 and 3.4.9 that resolve this vulnerability.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44172