Security Advisories for mautic/core in packagist
Moderate
about 2 months ago
Mautic Vulnerable to User Enumeration via Response Timing
packagist
mautic/core
Moderate
about 2 months ago
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
packagist
mautic/core
Moderate
about 2 months ago
Mautic vulnerable to secret data extraction via elfinder
packagist
mautic/core
Moderate
5 months ago
Mautic has an Open Redirect vulnerability on user unlock path.
packagist
mautic/core
Moderate
5 months ago
Mautic segment cloning doesn't have a proper permission check
packagist
mautic/core
Moderate
5 months ago
Mautic allows user name enumeration due to response time difference on password reset form
packagist
mautic/core
Moderate
5 months ago
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
packagist
mautic/core
Moderate
8 months ago
Mautic allows Relative Path Traversal in assets file upload
packagist
mautic/core
Critical
8 months ago
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
packagist
mautic/core
Moderate
about 1 year ago
Mautic allows users enumeration due to weak password login
packagist
mautic/core
Moderate
about 1 year ago
Mautic has insufficient authentication in upgrade flow
packagist
mautic/core-lib, mautic/core
Moderate
about 1 year ago
Mautic has an XSS in contact tracking and page hits report
packagist
mautic/core, mautic/core-lib
Moderate
about 1 year ago
Mautic vulnerable to XSS in contact/company tracking (no authentication)
packagist
mautic/core-lib, mautic/core
Moderate
about 1 year ago
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
packagist
mautic/core-lib, mautic/core
High
about 1 year ago
Mautic vulnerable to Improper Access Control in UI upgrade process
packagist
mautic/core, mautic/core-lib
Moderate
over 1 year ago
Mautic: MST-48 Server-Side Request Forgery in Asset section
packagist
mautic/core
High
over 1 year ago
Mautic Sensitive Data Exposure due to inadequate user permission settings
packagist
mautic/core
High
over 1 year ago
Mautic vulnerable to Relative Path Traversal / Arbitrary File Deletion due to GrapesJS builder
packagist
mautic/core
Moderate
over 1 year ago
Mautic vulnerable to cross-site scripting in notifications via saving Dashboards
packagist
mautic/core
High
over 1 year ago
Mautic vulnerable to stored cross-site scripting in description field
packagist
mautic/core
Critical
over 3 years ago
Cross-site Scripting vulnerability in Mautic's tracking pixel functionality
packagist
mautic/core
Moderate
over 4 years ago
Mautic vulnerable to secret data exfiltration via symfony parameters
packagist
mautic/core
Moderate
almost 5 years ago
CSV Injection vulnerability with exported contact lists in Mautic
packagist
mautic/core
High
almost 5 years ago
Mautic Sessions could be hijacked due to tracking contacts by an auto-incremented ID
packagist
mautic/core
High
almost 5 years ago
Disabled users able to log in with third party SSO plugin
packagist
mautic/core
Moderate
almost 5 years ago
XSS vulnerability in Author URL of themes in Mautic
packagist
mautic/core
Moderate
almost 5 years ago
Mautic users able to download any files from server using filemanager
packagist
mautic/core
Critical
almost 5 years ago
XSS vulnerability leveraged through referrers could allow un-authorized admin access in Mautic
packagist
mautic/core