Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mautic — Vulnerabilities & Security Advisories 40

Browse all 40 CVE security advisories affecting Mautic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Mautic is an open-source marketing automation platform designed to manage customer relationships through email campaigns, lead scoring, and personalized interactions. Its architecture, primarily built on PHP and Symfony, has historically exposed it to a significant volume of security flaws, currently totaling forty recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper access controls. Privilege escalation issues have also been documented, allowing lower-privileged users to gain administrative access. While the project maintains an active security response team that regularly patches these issues, the sheer number of disclosed CVEs highlights the risks associated with complex, community-driven codebases. Users must prioritize timely updates and strict configuration hardening to mitigate these persistent threats.

Found 36 results / 40 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-3105 SQL Injection in Contact Activity API Sorting — Mautic CWE-89 7.6 High 2026-02-24
CVE-2025-13828 Mautic user without privileged access to the Marketplace can install and uninstall composer packages — Mautic CWE-862 7.8AI High AI 2025-12-02
CVE-2025-13827 GrapesJsBuilder File Upload allows all file uploads — Mautic CWE-434 9.8AI Critical AI 2025-12-02
CVE-2025-9823 Reflected XSS in lead:addLeadTags - Quick Add — Mautic CWE-79 6.1AI Medium AI 2025-09-03
CVE-2025-9824 User Enumeration via Response Timing — Mautic CWE-204 5.9 Medium 2025-09-03
CVE-2025-9822 Secret data extraction via elfinder — Mautic CWE-283 5.5 Medium 2025-09-03
CVE-2025-9821 SSRF via webhook function — Mautic CWE-918 2.7 Low 2025-09-03
CVE-2025-5256 Open Redirect vulnerability on user unlock path — Mautic CWE-601 5.4 Medium 2025-05-28
CVE-2024-47055 Segment cloning doesn't have a proper permission check — Mautic CWE-862 4.3 Medium 2025-05-28
CVE-2024-47057 User name enumeration possible due to response time difference on password reset form — Mautic CWE-203 5.3 Medium 2025-05-28
CVE-2024-47056 Mautic does not shield .env files from web traffic — Mautic CWE-312 5.1 Medium 2025-05-28
CVE-2025-5257 Predictable Page Indexing Might Lead to Sensitive Data Exposure — Mautic CWE-1284 6.5 Medium 2025-05-28
CVE-2022-25770 Insufficient authentication in upgrade flow — Mautic CWE-306 7.8 High 2024-09-18
CVE-2024-47059 Users enumeration - weak password login — Mautic CWE-200 4.3 Medium 2024-09-18
CVE-2021-27917 XSS in contact tracking and page hits report — Mautic CWE-79 7.3 High 2024-09-18
CVE-2024-47050 XSS in contact/company tracking (no authentication) — Mautic CWE-79 5.4 Medium 2024-09-18
CVE-2024-47058 Cross-site Scripting (XSS) - stored (edit form HTML field) — Mautic CWE-79 2.9 Low 2024-09-18
CVE-2022-25768 Improper Access Control in UI upgrade process — Mautic CWE-287 7.0 High 2024-09-18
CVE-2022-25777 Server-Side Request Forgery in Asset section — Mautic CWE-918 6.5 Medium 2024-09-18
CVE-2022-25776 Sensitive Data Exposure due to inadequate user permission settings — Mautic CWE-276 8.3 High 2024-09-18
CVE-2022-25775 SQL Injection in dynamic Reports — Mautic CWE-89 6.6 Medium 2024-09-18
CVE-2022-25774 XSS in Notifications via saving Dashboards — Mautic CWE-79 4.8 Medium 2024-09-18
CVE-2022-25769 Improper regex in htaccess file — Mautic CWE-1284 7.2 High 2024-09-18
CVE-2021-27916 Relative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder) — Mautic CWE-22 8.1 High 2024-09-17
CVE-2021-27915 XSS Cross-site Scripting Stored (XSS) - Description field — Mautic CWE-80 7.6 High 2024-09-17
CVE-2024-3448 Improper Access Control Leads to Server-Side Request Forgery in Mautic — Mautic CWE-918 5.0 Medium 2024-04-10
CVE-2024-2731 Improper Access Control Issues Lead to Sensitive Data Exposure in Mautic — Mautic CWE-284 5.4 Medium 2024-04-10
CVE-2024-2730 Predictable Page Indexing Might Lead to Sensitive Data Exposure in Mautic — Mautic CWE-425 5.3 Medium 2024-04-10
CVE-2022-25772 Mautic 跨站脚本漏洞 — Mautic CWE-79 9.6 Critical 2022-06-20
CVE-2021-27914 Mautic 跨站脚本漏洞 — Mautic CWE-79 7.6 High 2022-06-01

This page lists every published CVE security advisory associated with Mautic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.