Mautic
Mautic: vulnerabilidades y CVE
Mautic tiene 22 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses7
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9811 | Media (5.4) | 0.23% | — | 29 may 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize… |
| CVE-2026-9809 | Alta (7.6) | 0.29% | — | 29 may 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms),… |
| CVE-2026-9808 | Alta (7.1) | 0.34% | — | 29 may 2026 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not… |
| CVE-2026-9559 | Crítica (9.9) | 0.93% | — | 29 may 2026 | A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended… |
| CVE-2026-9558 | Crítica (9.9) | 0.79% | — | 29 may 2026 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions… |
| CVE-2026-9557 | Media (6.4) | 0.23% | — | 29 may 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting… |
| CVE-2026-4776 | Alta (7.1) | 0.38% | — | 29 may 2026 | An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject… |
| CVE-2025-9822 | Media (5.5) | 0.24% | — | 3 sept 2025 | SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain… |
| CVE-2025-5256 | Media (5.4) | 0.24% | — | 28 may 2025 | SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially… |
| CVE-2024-47057 | Media (5.3) | 0.31% | — | 28 may 2025 | SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User… |
| CVE-2025-5257 | Media (6.5) | 0.35% | — | 28 may 2025 | SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended… |
| CVE-2024-47056 | Media (5.1) | 0.12% | — | 28 may 2025 | SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead to the disclosure of sensitive… |
| CVE-2024-2730 | Media (5.3) | 0.51% | — | 10 abr 2024 | Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated users under public preview URLs which could expose sensitive data. At the time of publication of the… |
| CVE-2020-35129 | Crítica (9) | 1.0% | — | 19 ene 2021 | Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally… |
| CVE-2018-8092 | Crítica (9.8) | 1.6% | — | 18 abr 2018 | Mautic before 2.13.0 allows CSV injection. |
| CVE-2018-8071 | Media (6.1) | 0.81% | — | 18 abr 2018 | Mautic before v2.13.0 has stored XSS via a theme config file. |
| CVE-2018-10189 | Alta (7.5) | 1.1% | — | 17 abr 2018 | An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-incremented ID. Thus, a third party can… |
| CVE-2017-1000506 | Media (6.1) | 1.1% | — | 9 feb 2018 | Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code. |
| CVE-2017-1000490 | Media (6.5) | 1.4% | — | 3 ene 2018 | Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to. |
| CVE-2017-1000489 | Alta (8.1) | 1.1% | — | 3 ene 2018 | Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address |
| CVE-2017-1000488 | Media (6.1) | 0.84% | — | 3 ene 2018 | Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form. |
| CVE-2017-1000046 | Alta (7.5) | 1.1% | — | 17 jul 2017 | Mautic 2.6.1 and earlier fails to set flags on session cookies |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.