Technology · Packagist
mautic/core (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in mautic/core (Packagist): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-9811, was published on 29 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
Latest mautic/core (Packagist) vulnerabilities
- CVE-2026-9811: Mautic stored XSS in project selector componentmediumCVSS 5.4EPSS 0.2%
- CVE-2026-9809: Mautic stored XSS in Projects component project tagshighCVSS 7.6EPSS 0.3%
- CVE-2026-9808: Mautic Core authorization bypass in API v2 endpointshighCVSS 7.1EPSS 0.3%
- CVE-2026-9559: Mautic path traversal in campaign import featurecriticalCVSS 9.9EPSS 0.9%
- CVE-2022-25773: Mautic allows Relative Path Traversal in assets file uploadlowCVSS 3.1EPSS 0.6%
- CVE-2024-47053: Mautic allows Improper Authorization in Reporting APIlowCVSS 3.1EPSS 0.7%
- CVE-2024-47051: Mautic allows Remote Code Execution and File Deletion in Asset UploadslowCVSS 3.1EPSS 1.8%
- CVE-2024-47059: Mautic allows users enumeration due to weak password loginlowCVSS 3.1EPSS 0.3%
- CVE-2022-25774: Mautic vulnerable to cross-site scripting in notifications via saving DashboardslowCVSS 3.1EPSS 0.4%
- CVE-2021-27915: Mautic vulnerable to stored cross-site scripting in description fieldlowCVSS 3.1EPSS 0.6%
- CVE-2022-25772: Cross-site Scripting vulnerability in Mautic's tracking pixel functionalitylowCVSS 3.1EPSS 62.3%
- CVE-2020-35129: Mautic stored Cross-site Scripting (XSS)lowCVSS 3.1EPSS 1.0%
- CVE-2017-1000506: Mautic Cross Site Scripting (XSS) vulnerabilitylowCVSS 3EPSS 1.1%
- CVE-2017-1000046: Sensitive Cookie Without HttpOnly and Secure FlaglowCVSS 3EPSS 1.1%
- CVE-2017-8874: Mautic Cross-Site Request Forgery (CSRF)lowCVSS 3EPSS 0.8%
- CVE-2021-27908: Mautic vulnerable to secret data exfiltration via symfony parameterslowCVSS 3.1EPSS 0.4%
- CVE-2018-8092: CSV Injection vulnerability with exported contact lists in MauticlowCVSS 3EPSS 1.7%
- CVE-2018-11200: XSS vulnerability in company name field in MauticlowCVSS 3.1EPSS 0.8%
- CVE-2017-1000488: Inline JS XSS vulnerability in MauticlowCVSS 3EPSS 0.8%
- CVE-2018-10189: Mautic Sessions could be hijacked due to tracking contacts by an auto-incremented IDlowCVSS 3EPSS 1.1%
- CVE-2017-1000489: Disabled users able to log in with third party SSO pluginlowCVSS 3EPSS 1.1%
- CVE-2018-8071: XSS vulnerability in theme config file in MauticlowCVSS 3EPSS 0.8%
- CVE-2018-11198: XSS vulnerability in Author URL of themes in MauticlowCVSS 3EPSS 0.9%
- CVE-2017-1000490: Mautic users able to download any files from server using filemanagerlowCVSS 3EPSS 1.4%
Most severe mautic/core (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-9559: Mautic path traversal in campaign import featurecriticalCVSS 9.9EPSS 0.9%
- CVE-2026-9809: Mautic stored XSS in Projects component project tagshighCVSS 7.6EPSS 0.3%
- CVE-2026-9808: Mautic Core authorization bypass in API v2 endpointshighCVSS 7.1EPSS 0.3%
- CVE-2026-9811: Mautic stored XSS in project selector componentmediumCVSS 5.4EPSS 0.2%
- CVE-2022-25772: Cross-site Scripting vulnerability in Mautic's tracking pixel functionalitylowCVSS 3.1EPSS 62.3%
- CVE-2024-47051: Mautic allows Remote Code Execution and File Deletion in Asset UploadslowCVSS 3.1EPSS 1.8%
- CVE-2020-35129: Mautic stored Cross-site Scripting (XSS)lowCVSS 3.1EPSS 1.0%
- CVE-2018-11200: XSS vulnerability in company name field in MauticlowCVSS 3.1EPSS 0.8%
- CVE-2024-47053: Mautic allows Improper Authorization in Reporting APIlowCVSS 3.1EPSS 0.7%
- CVE-2021-27915: Mautic vulnerable to stored cross-site scripting in description fieldlowCVSS 3.1EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/packagist-mautic-core.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "mautic/core (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/packagist-mautic-core, 28 September 2026.