Mautic
mautic
9 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally d...Show more |
Mautic before 2.13.0 allows CSV injection. |
Mautic before v2.13.0 has stored XSS via a theme config file. |
An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-incremented ID. Thus, a third party can manipul...Show more |
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code. |
2Acquia Mautic2Mautic MauticNov 21, 2024 Jan 3, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to. |
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address |
2Acquia Mautic2Mautic MauticNov 21, 2024 Jan 3, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form. |
Mautic 2.6.1 and earlier fails to set flags on session cookies |