Vulnerabilities in Mautic

41 results
Vexday analysis

Mautic apresenta 39 vulnerabilidades catalogadas, com 3 classificadas como críticas, mas nenhuma sob ataque ativo confirmado no momento. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de aplicações web, e a ausência de divulgações recentes (últimos 90 dias) sugere um cenário de risco estável, embora o volume moderado de críticas demande atenção em patches existentes.

CVE-2022-25772CRITICALA cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executableEPSS 61.4%CVE-2021-27909MEDIUMXSS vulnerability on password reset pageEPSS 4.1%CVE-2024-47051CRITICALRemote Code Execution & File Deletion in Asset UploadsEPSS 1.8%CVE-2021-27916HIGHRelative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)EPSS 0.8%CVE-2024-47053HIGHImproper Authorization in Reporting APIEPSS 0.7%CVE-2021-27910HIGHStored XSS vulnerability on Bounce Management CallbackEPSS 0.7%CVE-2021-27911HIGHXSS vulnerability on contacts viewEPSS 0.6%CVE-2021-27912HIGHXSS vulnerability on asset viewEPSS 0.6%CVE-2022-25775MEDIUMSQL Injection in dynamic ReportsEPSS 0.6%CVE-2021-27915HIGHXSS Cross-site Scripting Stored (XSS) - Description fieldEPSS 0.6%CVE-2022-25773MEDIUMRelative Path Traversal in assets file uploadEPSS 0.6%CVE-2024-2730MEDIUMPredictable Page Indexing Might Lead to Sensitive Data Exposure in MauticEPSS 0.5%CVE-2022-25769HIGHImproper regex in htaccess fileEPSS 0.5%CVE-2021-27913LOWUse of a Broken or Risky Cryptographic AlgorithmEPSS 0.5%CVE-2021-27914HIGHA cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascriptEPSS 0.4%CVE-2022-25777MEDIUMServer-Side Request Forgery in Asset sectionEPSS 0.4%CVE-2024-3448MEDIUMImproper Access Control Leads to Server-Side Request Forgery in MauticEPSS 0.4%CVE-2025-13827HIGHGrapesJsBuilder File Upload allows all file uploadsEPSS 0.4%CVE-2022-25776HIGHSensitive Data Exposure due to inadequate user permission settingsEPSS 0.4%CVE-2024-2731MEDIUMImproper Access Control Issues Lead to Sensitive Data Exposure in MauticEPSS 0.4%