Matomo is a web analytics platform deployed across a modestly sized but strategically placed set of instances, including self-hosted deployments and containerized variants, where it collects user interaction and site telemetry. Its vulnerability profile centers on web application input handling, with recurring weakness classes including cross-site scripting, path traversal, improper input validation, and exposure of sensitive information—characteristic of analytics platforms that process and display untrusted user and traffic data. The vendor's disclosures reflect a moderate tendency toward public exploit availability, indicating that flaws in this category warrant prompt patching attention. Defenders should prioritize inventory and access restrictions for Matomo instances, particularly those internet-facing, and apply vendor updates diligently given the sensitivity of the data they handle. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matomo over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4140HIGH Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Pl | Dec 22, 2009 | 7.5 | 78 | NO | YES |
CVE-2020-29578CRITICAL The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected version | Dec 8, 2020 | 9.8 | 30 | NO | NO |
CVE-2015-7816HIGH The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Requ | Nov 16, 2015 | 7.5 | 27 | NO | NO |
CVE-2009-4137HIGH The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the unserialize function, which allows remo | Dec 24, 2009 | 7.5 | 26 | NO | NO |
CVE-2010-1453MEDIUM Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter. | May 7, 2010 | 4.3 | 24 | NO | YES |
CVE-2013-0195MEDIUM Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability th | Nov 20, 2019 | 6.1 | 22 | NO | NO |
CVE-2013-0194MEDIUM Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability th | Nov 20, 2019 | 6.1 | 22 | NO | NO |
CVE-2013-0193MEDIUM Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability th | Nov 20, 2019 | 6.1 | 22 | NO | NO |
CVE-2010-2786MEDIUM Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified other impact via directory trave | Aug 2, 2010 | 6.8 | 22 | NO | NO |
CVE-2011-4941MEDIUM Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vectors. | Sep 18, 2012 | 6.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matomo.
Media articles that mention a CVE ID that affects a product developed by Matomo — matched by CVE ID, not by vendor name.