vciy

CVEs we hold for Mautic

Records whose assigning authority named Mautic as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-71245no title heldmautic
CVE-2026-3105SQL Injection in Contact Activity API SortingMautic
CVE-2025-9824User Enumeration via Response TimingMautic
CVE-2025-9823Reflected XSS in lead:addLeadTags - Quick AddMautic
CVE-2025-9822Secret data extraction via elfinderMautic
CVE-2025-9821SSRF via webhook functionMautic
CVE-2025-7381Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic imagesMautic
CVE-2025-5257Predictable Page Indexing Might Lead to Sensitive Data ExposureMautic
CVE-2025-5256Open Redirect vulnerability on user unlock pathMautic
CVE-2025-13828Mautic user without privileged access to the Marketplace can install and uninstall composer packagesMautic
CVE-2025-13827GrapesJsBuilder File Upload allows all file uploadsMautic
CVE-2024-47059Users enumeration - weak password loginMautic
CVE-2024-47058Cross-site Scripting (XSS) - stored (edit form HTML field)Mautic
CVE-2024-47057User name enumeration possible due to response time difference on password reset formMautic
CVE-2024-47056Mautic does not shield .env files from web trafficMautic
CVE-2024-47055Segment cloning doesn't have a proper permission checkMautic
CVE-2024-47053Improper Authorization in Reporting APImautic/core
CVE-2024-47051Remote Code Execution & File Deletion in Asset Uploadsmautic/core
CVE-2024-47050XSS in contact/company tracking (no authentication)Mautic
CVE-2024-3448Improper Access Control Leads to Server-Side Request Forgery in MauticMautic
CVE-2024-2731Improper Access Control Issues Lead to Sensitive Data Exposure in MauticMautic
CVE-2024-2730Predictable Page Indexing Might Lead to Sensitive Data Exposure in MauticMautic
CVE-2022-4426Mautic Integration For WooCommerce < 1.0.3 - Arbitrary Options Update via CSRFUnknown Mautic Integration for WooCommerce
CVE-2022-25777Server-Side Request Forgery in Asset sectionMautic
CVE-2022-25776Sensitive Data Exposure due to inadequate user permission settingsMautic
CVE-2022-25775SQL Injection in dynamic ReportsMautic
CVE-2022-25774XSS in Notifications via saving DashboardsMautic
CVE-2022-25773Relative Path Traversal in assets file uploadmautic/core
CVE-2022-25772no title heldMautic
CVE-2022-25770Insufficient authentication in upgrade flowMautic
CVE-2022-25769Improper regex in htaccess fileMautic
CVE-2022-25768Improper Access Control in UI upgrade processMautic
CVE-2021-27917XSS in contact tracking and page hits reportMautic
CVE-2021-27916Relative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)Mautic
CVE-2021-27915XSS Cross-site Scripting Stored (XSS) - Description fieldMautic
CVE-2021-27914no title heldMautic
CVE-2021-27913Use of a Broken or Risky Cryptographic AlgorithmMautic
CVE-2021-27912XSS vulnerability on asset viewMautic
CVE-2021-27911XSS vulnerability on contacts viewMautic
CVE-2021-27910Stored XSS vulnerability on Bounce Management CallbackMautic
CVE-2021-27909XSS vulnerability on password reset pageMautic
CVE-2021-27908no title heldMautic

42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.