Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-5hvg-w58j-545m
  • Packagist/mautic/core
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector 02 Jul
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-7h65-whp7-rgqf
  • Packagist/mautic/core
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component 02 Jul
  • Fix available
  • Severity - 7.6 (High)
GHSA-2jrw-c95w-h43g
  • Packagist/mautic/core
Mautic has an Authorization Bypass in API v2 Endpoints 02 Jul
  • Fix available
  • Severity - 7.1 (High)
GHSA-6r9h-4h75-7q4x
  • Packagist/mautic/core
Mautic vulnerable to Path Traversal via Campaign Import 02 Jul
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-9fx4-7cmj-47vg
  • Packagist/mautic/core
Mautic has Server-Side Template Injection (SSTI) in Theme Templates 02 Jul
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-jmv8-8j9j-rcpc
  • Packagist/mautic/core
Mautic Focus component Vulnerable to SSRF 02 Jul
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-fcmw-wx57-9p75
  • Packagist/mautic/core
Mautic has SQL Injection in API Contact Filtering 02 Jul
  • Fix available
  • Severity - 7.1 (High)
GHSA-r5j5-q42h-fc93
  • Packagist/mautic/core
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting 25 Feb
  • Fix available
  • Severity - 7.6 (High)
GHSA-3fq7-c5m8-g86x
  • Packagist/mautic/core
Mautic user without privileged access to the Marketplace can install and uninstall composer packages 02 Dec 2025
  • Fix available
  • Severity - 9.0 (Critical)
GHSA-3ggv-qwcp-j6xg
  • Packagist/mautic/core
Mautic Vulnerable to User Enumeration via Response Timing 03 Sep 2025
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-9v8p-m85m-f7mm
  • Packagist/mautic/core
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add 03 Sep 2025
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-438m-6mhw-hq5w
  • Packagist/mautic/core
Mautic vulnerable to secret data extraction via elfinder 03 Sep 2025
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-hj6f-7hp7-xg69
  • Packagist/mautic/core
Mautic vulnerable to SSRF via webhook function 03 Sep 2025
  • Fix available
  • Severity - 2.7 (Low)
GHSA-6vx9-9r2g-8373
  • Packagist/mautic/core
Mautic has an Open Redirect vulnerability on user unlock path. 28 May 2025
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-vph5-ghq3-q782
  • Packagist/mautic/core
Mautic segment cloning doesn't have a proper permission check 28 May 2025
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-424x-cxvh-wq9p
  • Packagist/mautic/core
Mautic allows user name enumeration due to response time difference on password reset form 28 May 2025
  • Fix available
  • Severity - 5.3 (Medium)