Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown

CVE-2021-27917

Disclosure Date: September 18, 2024 (last updated September 28, 2024)
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
Attacker Value
Unknown

CVE-2024-47058

Disclosure Date: September 18, 2024 (last updated September 28, 2024)
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
Attacker Value
Unknown

CVE-2024-47050

Disclosure Date: September 18, 2024 (last updated September 28, 2024)
Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.
Attacker Value
Unknown

CVE-2022-25776

Disclosure Date: September 18, 2024 (last updated September 25, 2024)
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.
Attacker Value
Unknown

CVE-2022-25775

Disclosure Date: September 18, 2024 (last updated September 24, 2024)
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
Attacker Value
Unknown

CVE-2022-25774

Disclosure Date: September 18, 2024 (last updated September 24, 2024)
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards.
Attacker Value
Unknown

CVE-2021-27916

Disclosure Date: September 17, 2024 (last updated October 03, 2024)
Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic.
Attacker Value
Unknown

CVE-2021-27915

Disclosure Date: September 17, 2024 (last updated September 29, 2024)
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.
Attacker Value
Unknown

CVE-2022-25772

Disclosure Date: June 20, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
Attacker Value
Unknown

CVE-2021-27914

Disclosure Date: June 01, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript