Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mautic

First CVE: Jul 17, 2017Active for: 9 yearsTotal CVEs: 9

Mautic is an open-source marketing automation platform whose vulnerability footprint concentrates in a single, widely deployed product that functions as a customer data and campaign management system in business environments. The vendor's disclosures skew toward serious outcomes with a notable share reaching critical severity, and they recur through application-layer weakness classes including cross-site scripting, improper authentication, path traversal, exposure of sensitive information, and CSV injection—patterns typical of web applications handling user input and customer data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mautic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
Jan 19, 2021
2,012 days ago

Self-Reporting Analysis

Of all the CVEs published by Mautic as a CNA, 0.0% affect products that Mautic develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 44 (100.0%)

Of all the CVEs published that affect products developed by Mautic, 0.0% are self-published by Mautic as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 9 (100.0%)

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-8092CRITICAL
Mautic before 2.13.0 allows CSV injection.
Apr 18, 20189.831NONO
CVE-2017-1000489HIGH
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
Jan 3, 20188.124NONO
CVE-2018-10189HIGH
An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-increme
Apr 17, 20187.523NONO
CVE-2020-35129CRITICAL
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example
Jan 19, 20219.022NONO
CVE-2017-1000490MEDIUM
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the serve
Jan 3, 20186.521NONO
CVE-2018-8071MEDIUM
Mautic before v2.13.0 has stored XSS via a theme config file.
Apr 18, 20186.120NONO
CVE-2017-1000506MEDIUM
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
Feb 9, 20186.120NONO
CVE-2017-1000488MEDIUM
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
Jan 3, 20186.120NONO
CVE-2017-1000046HIGH
Mautic 2.6.1 and earlier fails to set flags on session cookies
Jul 17, 20177.519NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
33%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mautic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mautic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mautic's Products

View all 1 CNAs →

Top CWEs