← back
CVE-2025-13828criticalCWE-862

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9epss 0.2%
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
nono source reports it
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
Mautic · Mautic