Mautic is an open-source marketing automation platform whose vulnerability footprint concentrates in a single, widely deployed product that functions as a customer data and campaign management system in business environments. The vendor's disclosures skew toward serious outcomes with a notable share reaching critical severity, and they recur through application-layer weakness classes including cross-site scripting, improper authentication, path traversal, exposure of sensitive information, and CSV injection—patterns typical of web applications handling user input and customer data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mautic over time
Of all the CVEs published by Mautic as a CNA, 0.0% affect products that Mautic develops as a vendor.
Of all the CVEs published that affect products developed by Mautic, 0.0% are self-published by Mautic as a CNA.
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8092CRITICAL Mautic before 2.13.0 allows CSV injection. | Apr 18, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-1000489HIGH Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address | Jan 3, 2018 | 8.1 | 24 | NO | NO |
CVE-2018-10189HIGH An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-increme | Apr 17, 2018 | 7.5 | 23 | NO | NO |
CVE-2020-35129CRITICAL Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example | Jan 19, 2021 | 9.0 | 22 | NO | NO |
CVE-2017-1000490MEDIUM Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the serve | Jan 3, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-8071MEDIUM Mautic before v2.13.0 has stored XSS via a theme config file. | Apr 18, 2018 | 6.1 | 20 | NO | NO |
CVE-2017-1000506MEDIUM Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code. | Feb 9, 2018 | 6.1 | 20 | NO | NO |
CVE-2017-1000488MEDIUM Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form. | Jan 3, 2018 | 6.1 | 20 | NO | NO |
CVE-2017-1000046HIGH Mautic 2.6.1 and earlier fails to set flags on session cookies | Jul 17, 2017 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mautic.
Media articles that mention a CVE ID that affects a product developed by Mautic — matched by CVE ID, not by vendor name.