Where
-Infinity
0

Vendor Risk Score

See how mautic compares to other vendors in security performance

View Risk Score →

Mautic MauticMautic: SQL Injection via field Parameter in Lead-by-Field-Value AJAX Endpoint

Risk 48
Severity
7.1
First published (updated )

Mautic MauticXSS

Risk 25
Severity
5.4
EPSS
0.13%
First published (updated )

Mautic MauticXSS

Risk 36
Severity
7.6
EPSS
0.16%
First published (updated )

Mautic Mautic 7 API v2An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platfor…

Risk 35
Severity
7.1
EPSS
0.20%
First published (updated )

Mautic MauticPath Traversal

Risk 59
Severity
9.9
EPSS
0.58%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/mautic/coreA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform …

Risk 59
Severity
9.9
EPSS
0.57%
First published (updated )

composer/mautic/coreSSRF

Risk 28
Severity
6.4
EPSS
0.15%
First published (updated )

composer/mautic/coreSQL Injection

Risk 48
Severity
7.1
First published (updated )

Acquia MauticSQL Injection in Contact Activity API Sorting

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )

composer/mautic/coreMautic user without privileged access to the Marketplace can install and uninstall composer packages

Risk 76
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/mautic/coreSecret data extraction via elfinder

Risk 29
Severity
5.5
EPSS
0.05%
First published (updated )

Mautic MauticExposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic images

Risk 19
Severity
5.3
EPSS
0.04%
First published (updated )

composer/mautic/coreSegment cloning doesn't have a proper permission check

Risk 22
Severity
4.3
First published (updated )

composer/mautic/coreUser name enumeration possible due to response time difference on password reset form

Risk 27
Severity
5.3
First published (updated )

composer/mautic/coreMautic does not shield .env files from web traffic

Risk 32
Severity
5.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/mautic/corePredictable Page Indexing Might Lead to Sensitive Data Exposure

Risk 28
Severity
6.5
EPSS
0.10%
First published (updated )

Mautic MauticImproper Access Control Leads to Server-Side Request Forgery in Mautic

Risk 18
Severity
5
EPSS
0.04%
First published (updated )

Mautic MauticImproper Access Control Issues Lead to Sensitive Data Exposure in Mautic

Risk 34
Severity
5.4
First published (updated )

Mautic MauticPredictable Page Indexing Might Lead to Sensitive Data Exposure in Mautic

Risk 27
Severity
5.3
First published (updated )

composer/mautic/coreXSS

Risk 78
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/mautic/coreXSS

Risk 38
Severity
6.1
First published (updated )

Mautic MauticMautic before 2.13.0 allows CSV injection.

Risk 86
Severity
9.8
First published (updated )

Mautic MauticInfoleak

Risk 44
Severity
7.5
First published (updated )

composer/mautic/coreXSS

Risk 39
Severity
6.1
First published (updated )

Acquia MauticPath Traversal

Risk 39
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Acquia MauticMautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still logi…

Risk 76
Severity
8.1
First published (updated )

Acquia MauticXSS

Risk 38
Severity
6.1
First published (updated )

composer/mautic/coreMautic prior to 2.1.1 fails to set flags on session cookies

Risk 45
Severity
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203