Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-3105
SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in th…
Mautic
4.4.19 / 5.2.10+
HIGH 8.1
CVE-2025-14472
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub:…
Acquia Content Hub
3.6.4 / 3.7.3+
HIGH 7.5
CVE-2025-9954
Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.
Dam
1.1.5+
HIGH 7.7
CVE-2024-47053
This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized acces…
Mautic
5.2.3+
CRITICAL 9.9
CVE-2024-47051
This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by au…
Mautic
5.2.3+
MEDIUM 5.4
CVE-2022-25773
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
* Improper…
Mautic
5.2.3+
HIGH 7.5
CVE-2022-25770
Mautic allows you to update the application via an upgrade script.
The upgrade logic isn't shielded off correctly, which may lead to vulnerable situ…
Mautic
4.4.13 / 5.1.1+
MEDIUM 5.4
CVE-2021-27917
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
Mautic
4.4.13 / 5.1.1+
MEDIUM 6.1
CVE-2024-47050
Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.
Mautic
4.4.13 / 5.1.1+
MEDIUM 6.5
CVE-2022-25768
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …
Mautic
4.4.13 / 5.1.1+
MEDIUM 6.5
CVE-2022-25777
Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a S…
Mautic
4.4.12 / 5.0.4+
CRITICAL 9.1
CVE-2022-25769
ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the …
Mautic
3.3.5 / 4.2.0+
HIGH 7.2
CVE-2022-25775
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle.
The user could retri…
Mautic
4.4.12 / 5.0.4+
MEDIUM 6.5
CVE-2022-25776
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing.
Us…
Mautic
4.4.12 / 5.0.4+
MEDIUM 5.4
CVE-2022-25774
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic.
Users could i…
Mautic
4.4.12+
HIGH 8.1
CVE-2021-27916
Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of…
Mautic
4.4.12 / 5.0.4+
CRITICAL 9.0
CVE-2021-27915
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a log…
Mautic
4.4.12+
MEDIUM 6.1
CVE-2022-25772EPSS 61%
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascri…
Mautic
4.3.0+
MEDIUM 6.1
CVE-2021-27909
For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in th…
Mautic
3.3.4+
MEDIUM 6.1
CVE-2021-27910
Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values s…
Mautic
3.3.4+
MEDIUM 6.1
CVE-2021-27911
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name and triggered when viewing a co…
Mautic
3.3.4+
MEDIUM 5.4
CVE-2021-27912
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and addin…
Mautic
3.3.4+
CRITICAL 9.6
CVE-2020-35125
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via …
Mautic
2.16.5 / 3.2.4+
CRITICAL 9.6
CVE-2020-35124
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript thr…
Mautic
3.2.4+
CRITICAL 9.0
CVE-2020-35128
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, inc…
Mautic
2.16.5 / 3.2.4+
MEDIUM 6.1
CVE-2018-11200
An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.
Mautic
Mitigation only
MEDIUM 6.1
CVE-2018-11198
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
Mautic
Mitigation only
HIGH 8.1
CVE-2017-1000489
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
Mautic
Mitigation only
MEDIUM 6.5
CVE-2017-1000490
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to d…
Mautic
No fix yet
MEDIUM 6.1
CVE-2017-1000488
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-p…
Mautic
No fix yet