mautic/core vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-9811Mediummautic/core: Mautic has Stored Cross-Site Scripting (XSS) in Project Option SelectorCVE-2026-9809Highmautic/core: Mautic has Stored Cross-Site Scripting (XSS) in Projects ComponentCVE-2026-9808Highmautic/core: Mautic has an Authorization Bypass in API v2 EndpointsCVE-2026-9559Criticalmautic/core: Mautic vulnerable to Path Traversal via Campaign ImportCVE-2026-9558Criticalmautic/core: Mautic has Server-Side Template Injection (SSTI) in Theme TemplatesCVE-2026-9557Mediummautic/core: Mautic Focus component Vulnerable to SSRFCVE-2026-4776Highmautic/core: Mautic has SQL Injection in API Contact FilteringCVE-2026-3105Highmautic/core: Mautic is Vulnerable to SQL Injection through Contact Activity API SortingCVE-2025-13828Criticalmautic/core: Mautic user without privileged access to the Marketplace can install and uninstall composer packagesCVE-2025-9824Mediummautic/core: Mautic Vulnerable to User Enumeration via Response TimingCVE-2025-9823Mediummautic/core: Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick AddCVE-2025-9822Mediummautic/core: Mautic vulnerable to secret data extraction via elfinderCVE-2025-9821Lowmautic/core: Mautic vulnerable to SSRF via webhook functionCVE-2025-5256Mediummautic/core: Mautic has an Open Redirect vulnerability on user unlock path.CVE-2024-47055Mediummautic/core: Mautic segment cloning doesn't have a proper permission checkCVE-2024-47057Mediummautic/core: Mautic allows user name enumeration due to response time difference on password reset formCVE-2024-47056Mediummautic/core: Mautic does not shield .env files from web trafficCVE-2025-5257Mediummautic/core: Mautic's Predictable Page Indexing Might Lead to Sensitive Data ExposureCVE-2022-25773Mediummautic/core: Mautic allows Relative Path Traversal in assets file uploadCVE-2024-47053Highmautic/core: Mautic allows Improper Authorization in Reporting APICVE-2024-47051Criticalmautic/core: Mautic allows Remote Code Execution and File Deletion in Asset UploadsCVE-2024-47059Mediummautic/core: Mautic allows users enumeration due to weak password loginCVE-2022-25770Mediummautic/core: Mautic has insufficient authentication in upgrade flowCVE-2021-27917Mediummautic/core-lib: Mautic has an XSS in contact tracking and page hits reportCVE-2024-47050Mediummautic/core: Mautic vulnerable to XSS in contact/company tracking (no authentication)

Stop the waste.
Protect your environment with Kodem.