Mautic
First CVE: Mar 23, 2021Active for: 5 years
44
CVEs Published
More CVEs Published than 54% of tracked CNAs
8.8
Avg CVEs / Year
More Avg CVEs / Year than 50% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Mautic as a CNA, 0.0% affect products that Mautic develops as a vendor.
100.0%
Self-reported: 0Third-party: 44
Of all the CVEs published that affect products developed by Mautic, 0.0% are self-published by Mautic as a CNA.
100.0%
Self-published: 0Published by other CNAs: 9
Trends Over Time
The number and severity of CVEs published by Mautic over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2021
5 years ago
Most Recent CVE
May 29, 2026
56 days ago
Top CVEs
All CVEs published by Mautic as a CNA, regardless of affected vendor or product.
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25772MEDIUM A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript | Jun 20, 2022 | 6.1 | 55 | NO | NO |
CVE-2026-9559CRITICAL A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows | May 29, 2026 | 9.9 | 39 | NO | NO |
CVE-2026-9558CRITICAL A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restriction | May 29, 2026 | 9.9 | 39 | NO | NO |
CVE-2026-9809HIGH A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as ca | May 29, 2026 | 7.6 | 32 | NO | NO |
CVE-2021-27909MEDIUM For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker t | Aug 30, 2021 | 6.1 | 32 | NO | YES |
CVE-2024-47051CRITICAL This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
* Remote | Feb 26, 2025 | 9.9 | 31 | NO | NO |
CVE-2026-3105HIGH SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Co | Feb 24, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-9808HIGH An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (su | May 29, 2026 | 7.1 | 29 | NO | NO |
CVE-2025-13828CRITICAL SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based up | Dec 2, 2025 | 9.0 | 29 | NO | NO |
CVE-2025-13827HIGH Summary
Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted.
ImpactIf the media folder is not restricted from r | Dec 2, 2025 | 8.8 | 28 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA44 CVEs
61%
20%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (4.5%)
Network42 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None27 (61.4%)
Unknown0 (0.0%)
Required15 (34.1%)
Privileges Required
Low24 (54.5%)
High6 (13.6%)
None14 (31.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (44 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.3% of CVEs· 86th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Mautic as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Mautic as a CNA — matched by CVE ID, not by organization name.