mautic/core
Mautic: Open Source Marketing Automation Software.
Activity
- Latest release
- 3d ago
- Total releases
- 203
- Cadence
- ~15 days
- Last 12 months
- 22
Reach
- Stars
- 10.3k
Details
- License
- GPL-3.0
- First release
- Dec 03, 2014
| Version | Released | |
|---|---|---|
7.2.0-rc2
pre
1 CVE
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev |
7.2.0-rc2
pre
Dependencies (3)
Changelog
Compare changes
|
|
7.1.3
patch
1 CVE
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.2.0-rc
pre
1 CVE
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.1.2
patch
1 CVE
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
6.0.9
patch
1 CVE
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
5.2.11
patch
1 CVE
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.1.1
patch
7 CVEs
CVE-2026-9811
GHSA-5hvg-w58j-545m
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. ImpactWhen another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature or the associated AJAX selector and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9809
GHSA-7h65-whp7-rgqf
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
7.6
/ 10
High
Network
Low
Low
Required
Changed
Low
High
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. ImpactWhen an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9808
GHSA-2jrw-c95w-h43g
Jul 02, 2026
Mautic has an Authorization Bypass in API v2 Endpoints
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
SummaryAn authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as ImpactAuthenticated API users with limited roles can read or modify restricted resources—including reports, contacts, and companies—that they do not own and should not have access to. This bypasses structural tenant and privilege boundaries on the platform. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, temporarily revoke API credentials or narrow access permissions for any users whose roles rely on owner-scope permission containment. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9559
GHSA-6r9h-4h75-7q4x
Jul 02, 2026
Mautic vulnerable to Path Traversal via Campaign Import
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. ImpactAn authenticated user with campaign import privileges ( Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this risk without upgrading, revoke campaign import permissions ( Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.1.0
minor
7 CVEs
CVE-2026-9811
GHSA-5hvg-w58j-545m
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. ImpactWhen another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature or the associated AJAX selector and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9809
GHSA-7h65-whp7-rgqf
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
7.6
/ 10
High
Network
Low
Low
Required
Changed
Low
High
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. ImpactWhen an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9808
GHSA-2jrw-c95w-h43g
Jul 02, 2026
Mautic has an Authorization Bypass in API v2 Endpoints
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
SummaryAn authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as ImpactAuthenticated API users with limited roles can read or modify restricted resources—including reports, contacts, and companies—that they do not own and should not have access to. This bypasses structural tenant and privilege boundaries on the platform. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, temporarily revoke API credentials or narrow access permissions for any users whose roles rely on owner-scope permission containment. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9559
GHSA-6r9h-4h75-7q4x
Jul 02, 2026
Mautic vulnerable to Path Traversal via Campaign Import
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. ImpactAn authenticated user with campaign import privileges ( Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this risk without upgrading, revoke campaign import permissions ( Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.0.2
patch
7 CVEs
CVE-2026-9811
GHSA-5hvg-w58j-545m
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. ImpactWhen another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature or the associated AJAX selector and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9809
GHSA-7h65-whp7-rgqf
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
7.6
/ 10
High
Network
Low
Low
Required
Changed
Low
High
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. ImpactWhen an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9808
GHSA-2jrw-c95w-h43g
Jul 02, 2026
Mautic has an Authorization Bypass in API v2 Endpoints
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
SummaryAn authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as ImpactAuthenticated API users with limited roles can read or modify restricted resources—including reports, contacts, and companies—that they do not own and should not have access to. This bypasses structural tenant and privilege boundaries on the platform. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, temporarily revoke API credentials or narrow access permissions for any users whose roles rely on owner-scope permission containment. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9559
GHSA-6r9h-4h75-7q4x
Jul 02, 2026
Mautic vulnerable to Path Traversal via Campaign Import
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. ImpactAn authenticated user with campaign import privileges ( Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this risk without upgrading, revoke campaign import permissions ( Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.1.0-rc
pre
7 CVEs
CVE-2026-9811
GHSA-5hvg-w58j-545m
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. ImpactWhen another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature or the associated AJAX selector and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9809
GHSA-7h65-whp7-rgqf
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
7.6
/ 10
High
Network
Low
Low
Required
Changed
Low
High
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. ImpactWhen an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9808
GHSA-2jrw-c95w-h43g
Jul 02, 2026
Mautic has an Authorization Bypass in API v2 Endpoints
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
SummaryAn authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as ImpactAuthenticated API users with limited roles can read or modify restricted resources—including reports, contacts, and companies—that they do not own and should not have access to. This bypasses structural tenant and privilege boundaries on the platform. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, temporarily revoke API credentials or narrow access permissions for any users whose roles rely on owner-scope permission containment. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9559
GHSA-6r9h-4h75-7q4x
Jul 02, 2026
Mautic vulnerable to Path Traversal via Campaign Import
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. ImpactAn authenticated user with campaign import privileges ( Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this risk without upgrading, revoke campaign import permissions ( Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.0.1
patch
7 CVEs
CVE-2026-9811
GHSA-5hvg-w58j-545m
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. ImpactWhen another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature or the associated AJAX selector and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9809
GHSA-7h65-whp7-rgqf
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
7.6
/ 10
High
Network
Low
Low
Required
Changed
Low
High
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. ImpactWhen an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9808
GHSA-2jrw-c95w-h43g
Jul 02, 2026
Mautic has an Authorization Bypass in API v2 Endpoints
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
SummaryAn authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as ImpactAuthenticated API users with limited roles can read or modify restricted resources—including reports, contacts, and companies—that they do not own and should not have access to. This bypasses structural tenant and privilege boundaries on the platform. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, temporarily revoke API credentials or narrow access permissions for any users whose roles rely on owner-scope permission containment. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9559
GHSA-6r9h-4h75-7q4x
Jul 02, 2026
Mautic vulnerable to Path Traversal via Campaign Import
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. ImpactAn authenticated user with campaign import privileges ( Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this risk without upgrading, revoke campaign import permissions ( Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
6.0.8
patch
3 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
5.2.10
patch
3 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev | ||
7.0.0
major
8 CVEs
CVE-2026-9811
GHSA-5hvg-w58j-545m
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. ImpactWhen another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature or the associated AJAX selector and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9809
GHSA-7h65-whp7-rgqf
Jul 02, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
7.6
/ 10
High
Network
Low
Low
Required
Changed
Low
High
None
SummaryA stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. ImpactWhen an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches do not contain the Projects feature and are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict project creation and modification permissions to trusted administrative users. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9808
GHSA-2jrw-c95w-h43g
Jul 02, 2026
Mautic has an Authorization Bypass in API v2 Endpoints
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
SummaryAn authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as ImpactAuthenticated API users with limited roles can read or modify restricted resources—including reports, contacts, and companies—that they do not own and should not have access to. This bypasses structural tenant and privilege boundaries on the platform. Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, temporarily revoke API credentials or narrow access permissions for any users whose roles rely on owner-scope permission containment. Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9559
GHSA-6r9h-4h75-7q4x
Jul 02, 2026
Mautic vulnerable to Path Traversal via Campaign Import
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. ImpactAn authenticated user with campaign import privileges ( Patched VersionsThis security issue has been addressed in the following release:
Note: Mautic 6.x, 5.x, and 4.x branches are not affected by this vulnerability. For general security support regarding legacy Mautic 4 releases, please refer to the ELTS page. WorkaroundsThere are no official workarounds. To mitigate this risk without upgrading, revoke campaign import permissions ( Affected versions
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev | ||
7.0.0-rc2
pre
2 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev | ||
6.0.7
patch
4 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev | ||
5.2.9
patch
4 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev | ||
7.0.0-rc
pre
2 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev | ||
7.0.0-beta
pre
2 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev | ||
6.0.6
patch
5 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev | ||
6.0.5
patch
5 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev | ||
5.2.8
patch
5 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev | ||
6.0.4
patch
9 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev | ||
7.0.0-alpha
pre
2 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev | ||
6.0.3
patch
9 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev | ||
5.2.7
patch
9 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev | ||
6.0.2
patch
9 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev | ||
5.2.6
patch
9 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev | ||
6.0.1
patch
14 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
5.2.5
patch
14 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
6.0.0
major
14 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
5.2.4
patch
14 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
6.0.0-rc
pre
11 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
6.0.0-beta2
pre
11 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
5.2.3
patch
14 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
5.2.2
patch
17 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev | ||
6.0.0-alpha
pre
11 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev | ||
5.2.1
patch
17 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev | ||
5.2.0
minor
17 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev | ||
5.1.1
patch
17 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev | ||
4.4.13
patch
16 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev | ||
5.1.0
minor
23 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47059
GHSA-8vff-35qm-qjvv
Sep 18, 2024
Mautic allows users enumeration due to weak password login
Medium
Network
Low
None
None
SummaryWhen logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided along side with weak password, the application responds with ’Invalid credentials’ notification. This difference could be used to perform username enumeration. PatchesUpdate to 5.1.1 or later. If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.1.0
Fixed in
5.1.1
References Updated Sep 19, 2024 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
5.0.4
patch
22 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
4.4.12
patch
21 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
5.0.3
patch
26 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2022-25777
GHSA-mgv8-w49f-822w
Apr 12, 2024
Mautic: MST-48 Server-Side Request Forgery in Asset section
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
High
ImpactPrior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 144 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25776
GHSA-qjx3-2g35-6hv8
Apr 12, 2024
Mautic Sensitive Data Exposure due to inadequate user permission settings
8.3
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
High
ImpactPrior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names. PatchesUpdate to 4.4.12 and 5.0.4 WorkaroundsNo Referenceshttps://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure Affected versions
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
+ 137 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25775
GHSA-jj6w-2cqg-7p94
Apr 12, 2024
Mautic SQL Injection in dynamic Reports
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNo References
Affected versions
2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
+ 81 more Show less
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2021-27916
GHSA-9fcx-cv56-w58p
Apr 12, 2024
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
High
Network
Low
Low
None
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic. PatchesUpdate to 4.4.12 or 5.0.4. WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
3.3.0
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
+ 37 more Show less
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Oct 02, 2024 · Source: OSV.dev | ||
4.4.11
patch
27 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2022-25777
GHSA-mgv8-w49f-822w
Apr 12, 2024
Mautic: MST-48 Server-Side Request Forgery in Asset section
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
High
ImpactPrior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 144 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25776
GHSA-qjx3-2g35-6hv8
Apr 12, 2024
Mautic Sensitive Data Exposure due to inadequate user permission settings
8.3
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
High
ImpactPrior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names. PatchesUpdate to 4.4.12 and 5.0.4 WorkaroundsNo Referenceshttps://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure Affected versions
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
+ 137 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25775
GHSA-jj6w-2cqg-7p94
Apr 12, 2024
Mautic SQL Injection in dynamic Reports
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNo References
Affected versions
2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
+ 81 more Show less
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2021-27916
GHSA-9fcx-cv56-w58p
Apr 12, 2024
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
High
Network
Low
Low
None
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic. PatchesUpdate to 4.4.12 or 5.0.4. WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
3.3.0
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
+ 37 more Show less
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Oct 02, 2024 · Source: OSV.dev
CVE-2022-25774
GHSA-fhcx-f7jg-jx3f
Apr 12, 2024
Mautic vulnerable to cross-site scripting in notifications via saving Dashboards
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards. PatchesUpdate to Mautic 4.4.12. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 137 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.12
References Updated Sep 18, 2024 · Source: OSV.dev
CVE-2021-27915
GHSA-2rc5-2755-v422
Apr 11, 2024
Mautic vulnerable to stored cross-site scripting in description field
High
Network
Low
Low
ImpactPrior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system. PatchesUpdate to 4.4.12 WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
+ 136 more Show less
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.12
References Updated Sep 30, 2024 · Source: OSV.dev | ||
5.0.2
patch
26 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2022-25777
GHSA-mgv8-w49f-822w
Apr 12, 2024
Mautic: MST-48 Server-Side Request Forgery in Asset section
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
High
ImpactPrior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 144 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25776
GHSA-qjx3-2g35-6hv8
Apr 12, 2024
Mautic Sensitive Data Exposure due to inadequate user permission settings
8.3
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
High
ImpactPrior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names. PatchesUpdate to 4.4.12 and 5.0.4 WorkaroundsNo Referenceshttps://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure Affected versions
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
+ 137 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25775
GHSA-jj6w-2cqg-7p94
Apr 12, 2024
Mautic SQL Injection in dynamic Reports
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNo References
Affected versions
2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
+ 81 more Show less
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2021-27916
GHSA-9fcx-cv56-w58p
Apr 12, 2024
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
High
Network
Low
Low
None
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic. PatchesUpdate to 4.4.12 or 5.0.4. WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
3.3.0
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
+ 37 more Show less
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Oct 02, 2024 · Source: OSV.dev | ||
5.0.1
patch
26 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2022-25777
GHSA-mgv8-w49f-822w
Apr 12, 2024
Mautic: MST-48 Server-Side Request Forgery in Asset section
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
High
ImpactPrior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 144 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25776
GHSA-qjx3-2g35-6hv8
Apr 12, 2024
Mautic Sensitive Data Exposure due to inadequate user permission settings
8.3
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
High
ImpactPrior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names. PatchesUpdate to 4.4.12 and 5.0.4 WorkaroundsNo Referenceshttps://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure Affected versions
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
+ 137 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25775
GHSA-jj6w-2cqg-7p94
Apr 12, 2024
Mautic SQL Injection in dynamic Reports
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNo References
Affected versions
2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
+ 81 more Show less
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2021-27916
GHSA-9fcx-cv56-w58p
Apr 12, 2024
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
High
Network
Low
Low
None
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic. PatchesUpdate to 4.4.12 or 5.0.4. WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
3.3.0
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
+ 37 more Show less
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Oct 02, 2024 · Source: OSV.dev | ||
5.0.0
major
26 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-9557
GHSA-jmv8-8j9j-rcpc
Jul 02, 2026
Mautic Focus component Vulnerable to SSRF
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummaryA Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component ( ImpactAn authenticated user with access to the Mautic panel can exploit this vulnerability to perform internal port probing or force the server to initiate requests to external or arbitrary internal destinations. This can enable internal network reconnaissance or mapping of firewalled infrastructure. Patched VersionsThis security issue has been fixed in the following releases:
Mautic strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets/local hosts is recommended. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 51 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4776
GHSA-fcmw-wx57-9p75
Jul 02, 2026
Mautic has SQL Injection in API Contact Filtering
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
None
Low
SummaryAn SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands. ImpactAn authenticated user with API access can exploit this vulnerability to execute arbitrary SQL queries against the underlying database. This allows unauthorized retrieval of sensitive database contents—including user credentials, system configurations, and personal identifiable information (PII) of contacts—bypassing standard data access permissions. Patched VersionsThis security issue has been fixed in the following releases:
We strongly recommend upgrading to the latest version corresponding to your release branch. WorkaroundsThere are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts. Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 134 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.0
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-13828
GHSA-3fq7-c5m8-g86x
Dec 02, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
Network
Low
Low
None
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 41 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
Fixed in
4.4.18
5.2.9
6.0.7
References Updated Dec 02, 2025 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2022-25777
GHSA-mgv8-w49f-822w
Apr 12, 2024
Mautic: MST-48 Server-Side Request Forgery in Asset section
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
High
ImpactPrior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 144 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25776
GHSA-qjx3-2g35-6hv8
Apr 12, 2024
Mautic Sensitive Data Exposure due to inadequate user permission settings
8.3
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
High
ImpactPrior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names. PatchesUpdate to 4.4.12 and 5.0.4 WorkaroundsNo Referenceshttps://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure Affected versions
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
+ 137 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25775
GHSA-jj6w-2cqg-7p94
Apr 12, 2024
Mautic SQL Injection in dynamic Reports
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNo References
Affected versions
2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
+ 81 more Show less
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2021-27916
GHSA-9fcx-cv56-w58p
Apr 12, 2024
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
High
Network
Low
Low
None
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic. PatchesUpdate to 4.4.12 or 5.0.4. WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
3.3.0
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
+ 37 more Show less
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Oct 02, 2024 · Source: OSV.dev | ||
5.0.0-rc2
pre
23 CVEs
CVE-2026-9558
GHSA-9fx4-7cmj-47vg
Jul 02, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ImpactAn authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. Patched VersionsThis security issue has been addressed in the following releases:
For users on Mautic 4.x, this fix is available in:
Mautic strongly recommend upgrading to a patched version immediately. WorkaroundsThere are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions ( Affected versions
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
+ 165 more Show less
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.10
5.2.11
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
7.0.1
7.0.2
7.1.0
7.1.0-rc
7.1.1
7.1.2
7.2.0-rc
Fixed in
5.2.11
6.0.9
7.1.2
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-3105
GHSA-r5j5-q42h-fc93
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
7.6
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
Low
SummaryThis advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf there are any questions or comments about this advisory: Email Mautic at security@mautic.org Affected versions
2.10.0
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
+ 128 more Show less
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
7.0.0
7.0.0-alpha
7.0.0-beta
7.0.0-rc
7.0.0-rc2
Fixed in
5.2.10
6.0.8
7.0.1
References
Updated Feb 25, 2026 · Source: OSV.dev
CVE-2025-9824
GHSA-3ggv-qwcp-j6xg
Sep 03, 2025
Mautic Vulnerable to User Enumeration via Response Timing
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when:
The fix introduces a WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References
Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9823
GHSA-9v8p-m85m-f7mm
Sep 03, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Medium
Network
Low
Low
SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. ReferencesAffected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9822
GHSA-438m-6mhw-hq5w
Sep 03, 2025
Mautic vulnerable to secret data extraction via elfinder
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-9821
GHSA-hj6f-7hp7-xg69
Sep 03, 2025
Mautic vulnerable to SSRF via webhook function
2.7
/ 10
Low
Network
Low
High
None
Unchanged
Low
None
None
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resourceshttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 31 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4
Fixed in
4.4.17
5.2.8
6.0.5
References
Updated Sep 03, 2025 · Source: OSV.dev
CVE-2025-5256
GHSA-6vx9-9r2g-8373
May 28, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to malicious websites, potentially leading to phishing attacks or the delivery of exploit kits. Open Redirection via MitigationUpdate Mautic to a version that properly validates or sanitizes the Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47055
GHSA-vph5-ghq3-q782
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the MitigationUpdate Mautic to a version that implements proper authorization checks for the WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 12 more Show less
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47057
GHSA-424x-cxvh-wq9p
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence. WorkaroundsNone If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
+ 155 more Show less
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2024-47056
GHSA-h2wg-v8wg-jhxh
May 28, 2025
Mautic does not shield .env files from web traffic
5.1
/ 10
Medium
Local
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive Sensitive Information Disclosure via MitigationUpdate Mautic to the latest Mautic version.
By default, Mautic does not use For Apache users: Ensure your web server is configured to respect For Nginx users: As Nginx does not inherently support
After modifying your Nginx configuration, remember to reload or restart your Nginx service for the changes to take effect. Affected versions
4.4.0
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
+ 26 more Show less
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2025-5257
GHSA-cqx4-9vqf-q3m8
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later. Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
+ 42 more Show less
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
Fixed in
4.4.16
5.2.6
6.0.2
References Updated May 28, 2025 · Source: OSV.dev
CVE-2022-25773
GHSA-4w2w-36vm-c8hf
Feb 26, 2025
Mautic allows Relative Path Traversal in assets file upload
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
SummaryThis advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47053
GHSA-8xv7-g2q3-fqgc
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SummaryThis advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data.
MitigationPlease update to Mautic 5.2.3 or later WorkaroundsDisable the API in Mautic. See documentation. Referenceshttps://cwe.mitre.org/data/definitions/285.html https://docs.mautic.org/en/5.2/configuration/settings.html#api-settings If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
+ 146 more Show less
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2024-47051
GHSA-73gx-x7r9-77x2
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryThis advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
MitigationPlease update to 5.2.3 or later. WorkaroundsNone Referenceshttps://owasp.org/www-community/attacks/Code_Injection https://owasp.org/www-community/attacks/Path_Traversal If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
+ 155 more Show less
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.13
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References
Updated Oct 16, 2025 · Source: OSV.dev
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
+ 148 more Show less
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 147 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
+ 112 more Show less
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 150 more Show less
1.0.0
1.0.0-beta
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
+ 133 more Show less
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2022-25777
GHSA-mgv8-w49f-822w
Apr 12, 2024
Mautic: MST-48 Server-Side Request Forgery in Asset section
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
High
ImpactPrior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
1.0.0
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 144 more Show less
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25776
GHSA-qjx3-2g35-6hv8
Apr 12, 2024
Mautic Sensitive Data Exposure due to inadequate user permission settings
8.3
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
High
ImpactPrior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names. PatchesUpdate to 4.4.12 and 5.0.4 WorkaroundsNo Referenceshttps://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure Affected versions
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.0-beta1
1.2.1
1.2.2
+ 137 more Show less
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.0.0
2.0.1
2.1.0
2.1.1
2.10.0
2.10.0-beta
2.10.1
2.11.0
2.11.0-beta
2.12.0
2.12.0-beta
2.12.1
2.12.1-beta
2.12.2
2.12.2-beta
2.13.0
2.13.0-beta
2.13.1
2.14.0
2.14.0-beta
2.14.1
2.14.1-beta
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.0-beta
2.9.1
2.9.2
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2022-25775
GHSA-jj6w-2cqg-7p94
Apr 12, 2024
Mautic SQL Injection in dynamic Reports
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems. PatchesUpdate to 4.4.12 or 5.0.4 WorkaroundsNo References
Affected versions
2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.0-beta
2.15.1
2.15.1-beta
2.15.2
2.15.2-beta
2.15.3
2.15.3-beta
2.16.0
+ 81 more Show less
2.16.0-beta
2.16.1
2.16.1-beta
2.16.2
2.16.2-beta
2.16.3
2.16.3-beta
2.16.4
2.16.5
3.0.0
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5
3.2.5-rc
3.3.0
3.3.0-rc
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Sep 18, 2024 · Source: OSV.dev
CVE-2021-27916
GHSA-9fcx-cv56-w58p
Apr 12, 2024
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
High
Network
Low
Low
None
ImpactPrior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files. This vulnerability exists in the implementation of the GrapesJS builder in Mautic. PatchesUpdate to 4.4.12 or 5.0.4. WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
3.3.0
3.3.1
3.3.2
3.3.2-rc
3.3.3
3.3.3-rc
3.3.4
3.3.5
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
+ 37 more Show less
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
Fixed in
4.4.12
5.0.4
References
Updated Oct 02, 2024 · Source: OSV.dev |