VendorsAcquiamauticany version
Vulnerabilities

Acquia Mautic any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2024-47051
Remote Code Execution & File Deletion in Asset Uploads
Published 2025-02-26 · Analyzed
9.9EPSS 0.018
CVE-2022-25772
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
Published 2022-06-20 · Modified
9.6EPSS 0.623
CVE-2020-35125
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).
Published 2021-02-09 · Modified
9.6EPSS 0.027
CVE-2020-35124
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.
Published 2021-01-28 · Modified
9.6EPSS 0.024
CVE-2022-25769
Improper regex in htaccess file
Published 2024-09-18 · Analyzed
9.1EPSS 0.005
CVE-2020-35128
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.
Published 2021-01-19 · Modified
9.0EPSS 0.017
CVE-2021-27915
XSS Cross-site Scripting Stored (XSS) - Description field
Published 2024-09-17 · Analyzed
9.0EPSS 0.006
CVE-2026-3105
SQL Injection in Contact Activity API Sorting
Published 2026-02-24 · Analyzed
8.8EPSS 0.004
CVE-2021-27911
XSS vulnerability on contacts view
Published 2021-08-30 · Modified
8.3EPSS 0.006
CVE-2022-25776
Sensitive Data Exposure due to inadequate user permission settings
Published 2024-09-18 · Analyzed
8.3EPSS 0.004
CVE-2021-27910
Stored XSS vulnerability on Bounce Management Callback
Published 2021-08-30 · Modified
8.2EPSS 0.007
CVE-2021-27916
Relative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)
Published 2024-09-17 · Analyzed
8.1EPSS 0.008
CVE-2022-25770
Insufficient authentication in upgrade flow
Published 2024-09-18 · Analyzed
7.8EPSS 0.003
CVE-2024-47053
Improper Authorization in Reporting API
Published 2025-02-26 · Analyzed
7.7EPSS 0.007
CVE-2021-27914
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript
Published 2022-06-01 · Modified
7.6EPSS 0.005
CVE-2021-27917
XSS in contact tracking and page hits report
Published 2024-09-18 · Analyzed
7.3EPSS 0.003
CVE-2022-25775
SQL Injection in dynamic Reports
Published 2024-09-18 · Analyzed
7.2EPSS 0.006
CVE-2021-27912
XSS vulnerability on asset view
Published 2021-08-30 · Modified
7.1EPSS 0.006
CVE-2022-25768
Improper Access Control in UI upgrade process
Published 2024-09-18 · Analyzed
7.0EPSS 0.003
CVE-2022-25777
Server-Side Request Forgery in Asset section
Published 2024-09-18 · Analyzed
6.5EPSS 0.004
CVE-2021-27909
XSS vulnerability on password reset page
Published 2021-08-30 · Modified
6.3EPSS 0.041
CVE-2024-47050
XSS in contact/company tracking (no authentication)
Published 2024-09-18 · Analyzed
6.1EPSS 0.003
CVE-2021-27908
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing parts of the application.
Published 2021-03-23 · Modified
5.8EPSS 0.003
CVE-2022-25773
Relative Path Traversal in assets file upload
Published 2025-02-26 · Analyzed
5.4EPSS 0.006
CVE-2022-25774
XSS in Notifications via saving Dashboards
Published 2024-09-18 · Analyzed
5.4EPSS 0.004
CVE-2024-47058
Cross-site Scripting (XSS) - stored (edit form HTML field)
Published 2024-09-18 · Analyzed
4.8EPSS 0.002
CVE-2024-47055
Segment cloning doesn't have a proper permission check
Published 2025-05-28 · Analyzed
4.3EPSS 0.003
CVE-2021-27913
Use of a Broken or Risky Cryptographic Algorithm
Published 2021-08-30 · Modified
3.5EPSS 0.005