Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Matomo

First CVE: Mar 25, 2009Active for: 17 yearsTotal CVEs: 25
24.9
VTI Score
Low

Matomo is a web analytics platform deployed across a modestly sized but strategically placed set of instances, including self-hosted deployments and containerized variants, where it collects user interaction and site telemetry. Its vulnerability profile centers on web application input handling, with recurring weakness classes including cross-site scripting, path traversal, improper input validation, and exposure of sensitive information—characteristic of analytics platforms that process and display untrusted user and traffic data. The vendor's disclosures reflect a moderate tendency toward public exploit availability, indicating that flaws in this category warrant prompt patching attention. Defenders should prioritize inventory and access restrictions for Matomo instances, particularly those internet-facing, and apply vendor updates diligently given the sensitivity of the data they handle. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Matomo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2009
17 years ago
Most Recent CVE
May 21, 2025
429 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-4140HIGH
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Pl
Dec 22, 20097.578NOYES
CVE-2020-29578CRITICAL
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected version
Dec 8, 20209.830NONO
CVE-2015-7816HIGH
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Requ
Nov 16, 20157.527NONO
CVE-2009-4137HIGH
The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the unserialize function, which allows remo
Dec 24, 20097.526NONO
CVE-2010-1453MEDIUM
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.
May 7, 20104.324NOYES
CVE-2013-0195MEDIUM
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability th
Nov 20, 20196.122NONO
CVE-2013-0194MEDIUM
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability th
Nov 20, 20196.122NONO
CVE-2013-0193MEDIUM
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability th
Nov 20, 20196.122NONO
CVE-2010-2786MEDIUM
Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified other impact via directory trave
Aug 2, 20106.822NONO
CVE-2011-4941MEDIUM
Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vectors.
Sep 18, 20126.821NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
80%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (32.0%)
Unknown17 (68.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (32.0%)
High0 (0.0%)
Unknown17 (68.0%)
User Interaction
None2 (8.0%)
Unknown17 (68.0%)
Required6 (24.0%)
Privileges Required
Low1 (4.0%)
High1 (4.0%)
None6 (24.0%)
Unknown17 (68.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
8.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Matomo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Matomo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Matomo's Products

View all 4 CNAs →

Top CWEs