Vulnerabilities (CVE)

Filtered by vendor Acquia Subscribe
Filtered by product Mautic
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000489 2 Acquia, Mautic 2 Mautic, Mautic 2021-01-25 6.8 MEDIUM 8.1 HIGH
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
CVE-2017-8874 1 Acquia 1 Mautic 2021-01-25 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts.