Vulnerabilidades en Mautic
41 resultadosAnálisis Vexday
Mautic apresenta 39 vulnerabilidades catalogadas, com 3 classificadas como críticas, mas nenhuma sob ataque ativo confirmado no momento. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de aplicações web, e a ausência de divulgações recentes (últimos 90 dias) sugere um cenário de risco estável, embora o volume moderado de críticas demande atenção em patches existentes.
CVE-2022-25774MEDIUMXSS in Notifications via saving DashboardsEPSS 0.4%CVE-2021-27908MEDIUMIn all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user EPSS 0.3%CVE-2024-47059MEDIUMUsers enumeration - weak password loginEPSS 0.3%CVE-2025-9823MEDIUMReflected XSS in lead:addLeadTags - Quick AddEPSS 0.3%CVE-2025-9821LOWSSRF via webhook functionEPSS 0.3%CVE-2025-5257MEDIUMPredictable Page Indexing Might Lead to Sensitive Data ExposureEPSS 0.3%CVE-2024-47050MEDIUMXSS in contact/company tracking (no authentication)EPSS 0.3%CVE-2026-3105HIGHSQL Injection in Contact Activity API SortingEPSS 0.3%CVE-2022-25768HIGHImproper Access Control in UI upgrade processEPSS 0.3%CVE-2025-9824MEDIUMUser Enumeration via Response TimingEPSS 0.3%CVE-2022-25770HIGHInsufficient authentication in upgrade flowEPSS 0.3%CVE-2021-27917HIGHXSS in contact tracking and page hits reportEPSS 0.3%CVE-2024-47057MEDIUMUser name enumeration possible due to response time difference on password reset formEPSS 0.3%CVE-2025-9822MEDIUMSecret data extraction via elfinderEPSS 0.2%CVE-2025-13828CRITICALMautic user without privileged access to the Marketplace can install and uninstall composer packagesEPSS 0.2%CVE-2025-7381MEDIUMExposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic imagesEPSS 0.2%CVE-2024-47055MEDIUMSegment cloning doesn't have a proper permission checkEPSS 0.2%CVE-2025-5256MEDIUMOpen Redirect vulnerability on user unlock pathEPSS 0.2%CVE-2024-47058LOWCross-site Scripting (XSS) - stored (edit form HTML field)EPSS 0.2%CVE-2026-71245HIGHMautic: SQL Injection via field Parameter in Lead-by-Field-Value AJAX EndpointEPSS 0.2%