CVEs we hold for Mautic
Records whose assigning authority named Mautic as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-7381Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic imagesMautic CVE-2025-5257Predictable Page Indexing Might Lead to Sensitive Data ExposureMautic CVE-2025-5256Open Redirect vulnerability on user unlock pathMautic CVE-2025-13828Mautic user without privileged access to the Marketplace can install and uninstall composer packagesMautic CVE-2025-13827GrapesJsBuilder File Upload allows all file uploadsMautic CVE-2024-47058Cross-site Scripting (XSS) - stored (edit form HTML field)Mautic CVE-2024-47057User name enumeration possible due to response time difference on password reset formMautic CVE-2024-47056Mautic does not shield .env files from web trafficMautic CVE-2024-47055Segment cloning doesn't have a proper permission checkMautic CVE-2024-47051Remote Code Execution & File Deletion in Asset Uploadsmautic/core CVE-2024-47050XSS in contact/company tracking (no authentication)Mautic CVE-2024-3448Improper Access Control Leads to Server-Side Request Forgery in MauticMautic CVE-2024-2731Improper Access Control Issues Lead to Sensitive Data Exposure in MauticMautic CVE-2024-2730Predictable Page Indexing Might Lead to Sensitive Data Exposure in MauticMautic CVE-2022-4426Mautic Integration For WooCommerce < 1.0.3 - Arbitrary Options Update via CSRFUnknown Mautic Integration for WooCommerce CVE-2022-25776Sensitive Data Exposure due to inadequate user permission settingsMautic CVE-2022-25773Relative Path Traversal in assets file uploadmautic/core CVE-2021-27916Relative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)Mautic CVE-2021-27915XSS Cross-site Scripting Stored (XSS) - Description fieldMautic CVE-2021-27910Stored XSS vulnerability on Bounce Management CallbackMautic 42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.