mautic/core-lib
Mautic Open Source Distribution
Activity
- Latest release
- 3d ago
- Total releases
- 85
- Cadence
- ~15 days
- Last 12 months
- 22
Reach
- Stars
- 6
Details
- License
- GPL-3.0
- First release
- Apr 25, 2021
| Version | Released | |
|---|---|---|
7.2.0-rc2
pre
|
7.2.0-rc2
pre
Dependencies (85)
+ 77 more
Changelog
Compare changes
|
|
7.1.3
patch
|
7.1.3
patch
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
7.2.0-rc
pre
|
7.2.0-rc
pre
Dependencies (81)
+ 73 more
Changelog
Compare changes
|
|
7.1.2
patch
| ||
6.0.9
patch
|
6.0.9
patch
Dependencies (88)
+ 80 more
Changelog
Compare changes
|
|
5.2.11
patch
|
5.2.11
patch
Dependencies (90)
+ 82 more
Changelog
Compare changes
|
|
7.1.1
patch
| ||
7.1.0
minor
| ||
7.0.2
patch
|
7.0.2
patch
Dependencies (81)
+ 73 more
Changelog
Compare changes
|
|
7.1.0-rc
pre
|
7.1.0-rc
pre
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
7.0.1
patch
| ||
6.0.8
patch
| ||
5.2.10
patch
| ||
7.0.0
major
| ||
7.0.0-rc2
pre
| ||
6.0.7
patch
| ||
5.2.9
patch
| ||
7.0.0-rc
pre
|
7.0.0-rc
pre
Dependencies (81)
+ 73 more
Changelog
Compare changes
|
|
7.0.0-beta
pre
| ||
6.0.6
patch
|
6.0.6
patch
Dependencies (88)
+ 80 more
Changelog
Compare changes
|
|
6.0.5
patch
| ||
5.2.8
patch
|
5.2.8
patch
Dependencies (90)
+ 82 more
Changelog
Compare changes
|
|
6.0.4
patch
| ||
7.0.0-alpha
pre
|
7.0.0-alpha
pre
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
6.0.3
patch
| ||
5.2.7
patch
| ||
6.0.2
patch
| ||
5.2.6
patch
| ||
6.0.1
patch
|
6.0.1
patch
Dependencies (88)
+ 80 more
Changelog
Compare changes
|
|
5.2.5
patch
|
5.2.5
patch
Dependencies (90)
+ 82 more
Changelog
Compare changes
|
|
6.0.0
major
| ||
5.2.4
patch
| ||
6.0.0-rc
pre
| ||
6.0.0-beta
pre
|
6.0.0-beta
pre
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
5.2.3
patch
| ||
5.2.2
patch
| ||
6.0.0-alpha
pre
|
6.0.0-alpha
pre
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
5.2.1
patch
| ||
5.2.0
minor
| ||
5.1.1
patch
|
5.1.1
patch
Dependencies (90)
+ 82 more
Changelog
Compare changes
|
|
4.4.13
patch
|
4.4.13
patch
Dependencies (88)
+ 80 more
Changelog
Compare changes
|
|
5.1.0
minor
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
5.0.4
patch
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev |
5.0.4
patch
Dependencies (88)
+ 80 more
Changelog
Compare changes
|
|
4.4.12
patch
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
5.0.3
patch
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
4.4.11
patch
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
5.0.2
patch
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev |
5.0.2
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
5.0.1
patch
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev |
5.0.1
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
5.0.0
major
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev | ||
5.0.0-rc2
pre
5 CVEs
CVE-2022-25770
GHSA-qf6m-6m4g-rmrc
Sep 18, 2024
Mautic has insufficient authentication in upgrade flow
Medium
Local
High
None
None
ImpactMautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable PatchesPlease upgrade to 4.4.1 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 21, 2025 · Source: OSV.dev
CVE-2021-27917
GHSA-xpc5-rr39-v8v2
Sep 18, 2024
Mautic has an XSS in contact tracking and page hits report
Medium
Network
Low
None
SummaryPrior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47050
GHSA-73gr-32wg-qhh7
Sep 18, 2024
Mautic vulnerable to XSS in contact/company tracking (no authentication)
Medium
Network
Low
None
SummaryPrior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. PatchesPlease update to 4.4.13 or 5.1.1 or later. WorkaroundsNone Referenceshttps://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2024-47058
GHSA-xv68-rrmw-9xwf
Sep 18, 2024
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Medium
Network
Low
None
ImpactWith access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone References
If you have any questions or comments about this advisory: Email us at security@mautic.org Affected versions
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
+ 32 more Show less
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Fixed in
4.4.13
5.1.1
References
Updated Sep 27, 2024 · Source: OSV.dev
CVE-2022-25768
GHSA-x3jx-5w6m-q2fc
Sep 18, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
Network
High
None
None
ImpactThe logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required. PatchesUpgrade to 4.4.13 or 5.1.1 or later. WorkaroundsNone. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.2.0-rc
4.2.0-rc1
+ 32 more Show less
4.2.1
4.2.2
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.1
4.4.1-alpha
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
Fixed in
4.4.13
5.1.1
References
Updated Feb 28, 2025 · Source: OSV.dev |