Products: 1
    Vulnerabilities: 38
    Known Exploited: 0
    5
    Critical Level Threats
    9
    High Level Threats
    19
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-71245

    Red Hat CNA-LR concluded that this CVE is not valid.

    Last Modified: Aug 17, 2026
    Published: Aug 05, 2026

    CVE-2026-9811

    A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. When another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard.

    Last Modified: May 29, 2026
    Published: May 29, 2026

    CVE-2026-9809

    Stored XSS in Mautic 7 Project Names Exposes Administrators

    Last Modified: May 29, 2026
    Published: May 29, 2026

    CVE-2026-9808

    Authorization Bypass in Mautic 7 API v2 Endpoints

    Last Modified: May 29, 2026
    Published: May 29, 2026

    CVE-2026-9559

    Path Traversal in Mautic 7 Campaign Import Enabling Remote Code Execution

    Last Modified: May 29, 2026
    Published: May 29, 2026
    Items Per Page
    Mautic Vulnerabilities & Security CVEs | CVE-DB