VYPR

Mautic

by Mautic

Source repositories

CVEs (60)

  • CVE-2026-9559CriMay 29, 2026
    risk 0.64cvss 9.9epss 0.01

    A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import…

  • CVE-2026-9558CriMay 29, 2026
    risk 0.64cvss 9.9epss 0.01

    A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute…

  • CVE-2020-35125CriFeb 9, 2021
    risk 0.63cvss 9.6epss 0.03

    A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).

  • CVE-2022-25772CriJun 20, 2022
    risk 0.60cvss 9.6epss 0.61

    A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript

  • CVE-2025-13828CriDec 2, 2025
    risk 0.59cvss epss 0.00

    SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain…

  • CVE-2020-35129CriJan 19, 2021
    risk 0.59cvss 9.0epss 0.01

    Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually…

  • CVE-2020-35128CriJan 19, 2021
    risk 0.59cvss 9.0epss 0.02

    Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions…

  • CVE-2025-13827HigDec 2, 2025
    risk 0.57cvss epss 0.00

    Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.

  • CVE-2018-8092CriApr 18, 2018
    risk 0.57cvss 9.8epss 0.02

    Mautic before 2.13.0 allows CSV injection.

  • CVE-2017-8874HigMay 10, 2017
    risk 0.57cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts.

  • CVE-2020-35124CriJan 28, 2021
    risk 0.56cvss 9.6epss 0.02

    A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.

  • CVE-2021-27911HigAug 30, 2021
    risk 0.54cvss 8.3epss 0.01

    Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name and triggered when viewing a contact's details page then clicking on the action drop down and hovering over the Campaigns button. Contact first and last name can…

  • CVE-2024-47051CriFeb 26, 2025
    risk 0.52cvss 9.1epss 0.02

    This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote Code Execution (RCE) via Asset Upload: A Remote Code Execution vulnerability has been identified…

  • CVE-2026-9809HigMay 29, 2026
    risk 0.49cvss 7.6epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization.…

  • CVE-2021-27914HigJun 1, 2022
    risk 0.49cvss 7.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript

  • CVE-2018-10189HigApr 17, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-incremented ID. Thus, a third party can manipulate the cookie value with +1 to systematically assume being…

  • CVE-2017-1000046HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.01

    Mautic 2.6.1 and earlier fails to set flags on session cookies

  • CVE-2022-25776HigSep 18, 2024
    risk 0.47cvss 8.3epss 0.00

    Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.

  • CVE-2022-25769HigSep 18, 2024
    risk 0.47cvss 7.2epss 0.01

    ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.

  • CVE-2026-71245HigAug 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with InputHelper::clean (which HTML-entity-encodes quotes and angle brackets but does not restrict other characters), and passes it into…

Page 1 of 3