Mautic

Mautic

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 29.05.2026 10:41:29
  • Zuletzt bearbeitet 29.05.2026 15:39:34

A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX be...

  • EPSS 0.16%
  • Veröffentlicht 29.05.2026 10:36:38
  • Zuletzt bearbeitet 29.05.2026 15:39:34

A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered w...

  • EPSS 0.2%
  • Veröffentlicht 29.05.2026 10:30:23
  • Zuletzt bearbeitet 29.05.2026 15:39:34

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows l...

  • EPSS 0.58%
  • Veröffentlicht 29.05.2026 10:19:48
  • Zuletzt bearbeitet 29.05.2026 15:39:34

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authentica...

  • EPSS 0.44%
  • Veröffentlicht 29.05.2026 10:01:36
  • Zuletzt bearbeitet 29.05.2026 15:39:34

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can...

  • EPSS 0.14%
  • Veröffentlicht 29.05.2026 09:38:40
  • Zuletzt bearbeitet 29.05.2026 15:39:34

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network r...

  • EPSS 0.22%
  • Veröffentlicht 29.05.2026 06:58:24
  • Zuletzt bearbeitet 29.05.2026 15:39:34

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.

  • EPSS 0.29%
  • Veröffentlicht 24.02.2026 18:39:03
  • Zuletzt bearbeitet 27.02.2026 03:11:21

SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determinin...

  • EPSS 0.23%
  • Veröffentlicht 02.12.2025 16:54:58
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can ins...

  • EPSS 0.39%
  • Veröffentlicht 02.12.2025 16:54:39
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.