Mautic
by Mautic
Source repositories
CVEs (60)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9808 | Hig | 0.46 | 7.1 | 0.00 | May 29, 2026 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated… | ||
| CVE-2026-4776 | Hig | 0.46 | 7.1 | 0.00 | May 29, 2026 | An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. | ||
| CVE-2021-27916 | Hig | 0.46 | 8.1 | 0.01 | Sep 17, 2024 | Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or… | ||
| CVE-2021-27912 | Hig | 0.46 | 7.1 | 0.01 | Aug 30, 2021 | Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit… | ||
| CVE-2021-27910 | Hig | 0.46 | 8.2 | 0.01 | Aug 30, 2021 | Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values submitted in the "error" and "error_related_to" parameters of the POST request of the bounce management callback will be… | ||
| CVE-2017-1000489 | Hig | 0.46 | 8.1 | 0.01 | Jan 3, 2018 | Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address | ||
| CVE-2022-25770 | Hig | 0.44 | 7.8 | 0.00 | Sep 18, 2024 | Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable. | ||
| CVE-2024-47053 | Hig | 0.43 | 7.7 | 0.01 | Feb 26, 2025 | This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data. * Improper Authorization: An authorization flaw exists in Mautic's API Authorization… | ||
| CVE-2026-9557 | Med | 0.42 | 6.4 | 0.00 | May 29, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing… | ||
| CVE-2026-3105 | Hig | 0.42 | 7.6 | 0.00 | Feb 24, 2026 | SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not… | ||
| CVE-2025-5257 | Med | 0.42 | 6.5 | 0.00 | May 28, 2025 | SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. … | ||
| CVE-2021-27915 | Hig | 0.42 | 7.6 | 0.01 | Sep 17, 2024 | Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system. | ||
| CVE-2021-27917 | Hig | 0.40 | 7.3 | 0.00 | Sep 18, 2024 | Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. | ||
| CVE-2018-11200 | Med | 0.40 | 6.1 | 0.01 | Sep 20, 2019 | An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field. | ||
| CVE-2018-11198 | Med | 0.40 | 6.1 | 0.01 | Sep 6, 2019 | An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json. | ||
| CVE-2017-1000506 | Med | 0.40 | 6.1 | 0.01 | Feb 9, 2018 | Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code. | ||
| CVE-2022-25768 | Hig | 0.39 | 7.0 | 0.00 | Sep 18, 2024 | The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of… | ||
| CVE-2021-27908 | Med | 0.38 | 5.8 | 0.00 | Mar 23, 2021 | In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing… | ||
| CVE-2022-25775 | Med | 0.36 | 6.6 | 0.01 | Sep 18, 2024 | Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems. | ||
| CVE-2026-9811 | Med | 0.35 | 5.4 | 0.00 | May 29, 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the… |
- risk 0.46cvss 7.1epss 0.00
An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated…
- risk 0.46cvss 7.1epss 0.00
An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.
- risk 0.46cvss 8.1epss 0.01
Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or…
- risk 0.46cvss 7.1epss 0.01
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit…
- risk 0.46cvss 8.2epss 0.01
Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values submitted in the "error" and "error_related_to" parameters of the POST request of the bounce management callback will be…
- risk 0.46cvss 8.1epss 0.01
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
- risk 0.44cvss 7.8epss 0.00
Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
- risk 0.43cvss 7.7epss 0.01
This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data. * Improper Authorization: An authorization flaw exists in Mautic's API Authorization…
- risk 0.42cvss 6.4epss 0.00
A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing…
- risk 0.42cvss 7.6epss 0.00
SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not…
- risk 0.42cvss 6.5epss 0.00
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. …
- risk 0.42cvss 7.6epss 0.01
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.
- risk 0.40cvss 7.3epss 0.00
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
- risk 0.40cvss 6.1epss 0.01
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
- risk 0.39cvss 7.0epss 0.00
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of…
- risk 0.38cvss 5.8epss 0.00
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing…
- risk 0.36cvss 6.6epss 0.01
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
- risk 0.35cvss 5.4epss 0.00
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the…
Page 2 of 3