Loading HuntDB...

mautic

1 Product 24 CVEs

CVE Severity Distribution (All Time)

Critical
1
High
11
Medium
10
Low
2

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 13 CVEs

Recent CVEs

View all
CVE-2022-25770 HIGH 9 months ago

Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situ…

CVE-2024-47059 MEDIUM 9 months ago

When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However …

CVE-2021-27917 HIGH 9 months ago

Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.

CVE-2024-47050 MEDIUM 9 months ago

Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.

CVE-2024-47058 LOW 9 months ago

With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive informat…

CVE-2022-25768 HIGH 9 months ago

The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …

CVE-2022-25777 MEDIUM 9 months ago

Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a S…

CVE-2022-25776 HIGH 9 months ago

Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Us…

CVE-2022-25775 MEDIUM 9 months ago

Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retri…

CVE-2022-25774 MEDIUM 9 months ago

Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could i…