Acquia maintains a focused portfolio of digital experience and content management platforms, particularly Mautic, Commons, and its content hub offerings, that serve marketing automation and community collaboration use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while the exposure recurs across its product line through application-layer weakness classes including cross-site scripting, cross-site request forgery, path traversal, missing authorization, and sensitive-information exposure that are characteristic of web-based content and marketing platforms. Defenders should prioritize advisories from this vendor given the severity tendency and treat exposed instances as requiring prompt patching; live exploitation activity, KEV status, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acquia over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25772MEDIUM A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript | Jun 20, 2022 | 6.1 | 55 | NO | NO |
CVE-2021-27909MEDIUM For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker t | Aug 30, 2021 | 6.1 | 32 | NO | YES |
CVE-2024-47051CRITICAL This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
* Remote | Feb 26, 2025 | 9.9 | 31 | NO | NO |
CVE-2026-3105HIGH SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Co | Feb 24, 2026 | 8.8 | 30 | NO | NO |
CVE-2020-35124CRITICAL A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asse | Jan 28, 2021 | 9.6 | 29 | NO | NO |
CVE-2020-35128CRITICAL Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For exam | Jan 19, 2021 | 9.0 | 29 | NO | NO |
CVE-2020-35125CRITICAL A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different att | Feb 9, 2021 | 9.6 | 28 | NO | NO |
CVE-2017-8874HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns | May 10, 2017 | 8.8 | 28 | NO | NO |
CVE-2025-14472HIGH Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub: from 0.0.0 before 3.6.4, from | Jan 28, 2026 | 8.1 | 26 | NO | NO |
CVE-2021-27915CRITICAL Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the | Sep 17, 2024 | 9.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acquia.
Media articles that mention a CVE ID that affects a product developed by Acquia — matched by CVE ID, not by vendor name.