A node.js driver for mysql. It is written in JavaScript, does not require compiling, and is 100% MIT licensed.
85%
Total Score
77
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10224 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. mysql is vulnerable to SQL Injection in versions 0.0.1 - 2.18.1. | 0.0.1 - 2.18.1 | High |
CVE-2019-14939 mysql is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 2.17.1 - 2.17.1. | 2.17.1 - 2.17.1 | Medium |
CVE-2015-9244 mysql is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.0.0-alpha7. | 0.0.0 - 2.0.0-alpha7 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
sqlstring Version 2.3.1 | — | — |
safe-buffer Version 5.1.2 | — | — |
bignumber.js Version 9.0.0 | — | — |
readable-stream Version 2.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant