Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Acquia

First CVE: Oct 31, 2012Active for: 14 yearsTotal CVEs: 42
32.2
VTI Score
Medium

Acquia maintains a focused portfolio of digital experience and content management platforms, particularly Mautic, Commons, and its content hub offerings, that serve marketing automation and community collaboration use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while the exposure recurs across its product line through application-layer weakness classes including cross-site scripting, cross-site request forgery, path traversal, missing authorization, and sensitive-information exposure that are characteristic of web-based content and marketing platforms. Defenders should prioritize advisories from this vendor given the severity tendency and treat exposed instances as requiring prompt patching; live exploitation activity, KEV status, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Acquia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2012
13 years ago
Most Recent CVE
Feb 24, 2026
150 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-25772MEDIUM
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
Jun 20, 20226.155NONO
CVE-2021-27909MEDIUM
For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker t
Aug 30, 20216.132NOYES
CVE-2024-47051CRITICAL
This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote
Feb 26, 20259.931NONO
CVE-2026-3105HIGH
SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Co
Feb 24, 20268.830NONO
CVE-2020-35124CRITICAL
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asse
Jan 28, 20219.629NONO
CVE-2020-35128CRITICAL
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For exam
Jan 19, 20219.029NONO
CVE-2020-35125CRITICAL
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different att
Feb 9, 20219.628NONO
CVE-2017-8874HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns
May 10, 20178.828NONO
CVE-2025-14472HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub: from 0.0.0 before 3.6.4, from
Jan 28, 20268.126NONO
CVE-2021-27915CRITICAL
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the
Sep 17, 20249.026NONO
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
57%
24%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.4%)
Network38 (90.5%)
Unknown3 (7.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (90.5%)
High1 (2.4%)
Unknown3 (7.1%)
User Interaction
None18 (42.9%)
Unknown3 (7.1%)
Required21 (50.0%)
Privileges Required
Low16 (38.1%)
High5 (11.9%)
None18 (42.9%)
Unknown3 (7.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.4% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Acquia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Acquia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Acquia's Products

View all 4 CNAs →

Top CWEs