Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-3105 SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in th… Mautic 4.4.19 / 5.2.10+ Fix from $1,9502026-02-24 HIGH 8.1 CVE-2025-14472 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub:… Acquia Content Hub 3.6.4 / 3.7.3+ Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-9954 Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5. Dam 1.1.5+ Fix from $1,9502025-10-30 HIGH 7.7 CVE-2024-47053 This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized acces… Mautic 5.2.3+ Fix from $1,9502025-02-26 CRITICAL 9.9 CVE-2024-47051 This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by au… Mautic 5.2.3+ Fix from $2,3002025-02-26 MEDIUM 5.4 CVE-2022-25773 This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper… Mautic 5.2.3+ Fix from $1,6002025-02-26 HIGH 7.5 CVE-2022-25770 Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situ… Mautic 4.4.13 / 5.1.1+ Fix from $1,9502024-09-18 MEDIUM 5.4 CVE-2021-27917 Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. Mautic 4.4.13 / 5.1.1+ Fix from $1,6002024-09-18 MEDIUM 6.1 CVE-2024-47050 Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. Mautic 4.4.13 / 5.1.1+ Fix from $1,6002024-09-18 MEDIUM 6.5 CVE-2022-25768 The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. … Mautic 4.4.13 / 5.1.1+ Fix from $1,6002024-09-18 MEDIUM 6.5 CVE-2022-25777 Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a S… Mautic 4.4.12 / 5.0.4+ Fix from $1,6002024-09-18 CRITICAL 9.1 CVE-2022-25769 ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the … Mautic 3.3.5 / 4.2.0+ Fix from $2,3002024-09-18 HIGH 7.2 CVE-2022-25775 Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retri… Mautic 4.4.12 / 5.0.4+ Fix from $1,9502024-09-18 MEDIUM 6.5 CVE-2022-25776 Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Us… Mautic 4.4.12 / 5.0.4+ Fix from $1,6002024-09-18 MEDIUM 5.4 CVE-2022-25774 Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could i… Mautic 4.4.12+ Fix from $1,6002024-09-18 HIGH 8.1 CVE-2021-27916 Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of… Mautic 4.4.12 / 5.0.4+ Fix from $1,9502024-09-17 CRITICAL 9.0 CVE-2021-27915 Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a log… Mautic 4.4.12+ Fix from $2,3002024-09-17 MEDIUM 6.1 CVE-2022-25772EPSS 61% A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascri… Mautic 4.3.0+ Fix from $1,6002022-06-20 MEDIUM 6.1 CVE-2021-27909 For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in th… Mautic 3.3.4+ Fix from $1,6002021-08-30 MEDIUM 6.1 CVE-2021-27910 Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values s… Mautic 3.3.4+ Fix from $1,6002021-08-30 MEDIUM 6.1 CVE-2021-27911 Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name and triggered when viewing a co… Mautic 3.3.4+ Fix from $1,6002021-08-30 MEDIUM 5.4 CVE-2021-27912 Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and addin… Mautic 3.3.4+ Fix from $1,6002021-08-30 CRITICAL 9.6 CVE-2020-35125 A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via … Mautic 2.16.5 / 3.2.4+ Fix from $2,3002021-02-09 CRITICAL 9.6 CVE-2020-35124 A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript thr… Mautic 3.2.4+ Fix from $2,3002021-01-28 CRITICAL 9.0 CVE-2020-35128 Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, inc… Mautic 2.16.5 / 3.2.4+ Fix from $2,3002021-01-19 MEDIUM 6.1 CVE-2018-11200 An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field. Mautic Mitigation only Fix from $1,6002019-09-20 MEDIUM 6.1 CVE-2018-11198 An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json. Mautic Mitigation only Fix from $1,6002019-09-06 HIGH 8.1 CVE-2017-1000489 Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address Mautic Mitigation only Fix from $1,9502018-01-03 MEDIUM 6.5 CVE-2017-1000490 Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to d… Mautic No fix yet Fix from $1,6002018-01-03 MEDIUM 6.1 CVE-2017-1000488 Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-p… Mautic No fix yet Fix from $1,6002018-01-03