Mautic
This hub aggregates every CVE we track for Mautic, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
52
CVEs tracked
7
Critical
17
High
0
In CISA KEV
Severity distribution
MEDIUM25HIGH17CRITICAL7LOW3
Monthly trend
13
0
0
0
0
3
0
0
5
0
1
0
3
0
0
0
0
1
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Mautic.
- CVE-2026-3105SQL Injection in Contact Activity API Sorting7.6
- CVE-2025-9824User Enumeration via Response Timing5.9
- CVE-2025-9822Secret data extraction via elfinder5.5
- CVE-2025-9821SSRF via webhook function2.7
- CVE-2025-7381Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic images5.3
- CVE-2025-5256Open Redirect vulnerability on user unlock path5.4
- CVE-2024-47055Segment cloning doesn't have a proper permission check4.3
- CVE-2024-47057User name enumeration possible due to response time difference on password reset form5.3
- CVE-2024-47056Mautic does not shield .env files from web traffic5.1
- CVE-2025-5257Predictable Page Indexing Might Lead to Sensitive Data Exposure6.5
- CVE-2024-47051Remote Code Execution & File Deletion in Asset Uploads9.1
- CVE-2024-47053Improper Authorization in Reporting API7.7
- CVE-2022-25773Relative Path Traversal in assets file upload4.3
- CVE-2022-25770Insufficient authentication in upgrade flow7.8
- CVE-2024-47059Users enumeration - weak password login4.3
Product normalization is registry-driven with AI assist and human review. How it works