6.5

CVSS3.1

CVE-2022-25777 - Server-Side Request Forgery in Asset section

Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability.

๐Ÿ“… Published: Sept. 18, 2024, 3:13 p.m. ๐Ÿ”„ Last Modified: Feb. 27, 2025, 7:30 p.m.

8.3

CVSS3.1

CVE-2022-25776 - Sensitive Data Exposure due to inadequate user permission settings

Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.

๐Ÿ“… Published: Sept. 18, 2024, 3:06 p.m. ๐Ÿ”„ Last Modified: Sept. 24, 2024, 3:19 p.m.

7.8

CVSS3.1

CVE-2024-45858 -

An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it โ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 3:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2022-25775 - SQL Injection in dynamic Reports

Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.

๐Ÿ“… Published: Sept. 18, 2024, 3:01 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2024, 11:22 p.m.

9.2

CVSS4.0

CVE-2024-6878 - Directory Browsing in Eliz Software's Panel

Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations.This issue affects Panel: before v2.3.24.

๐Ÿ“… Published: Sept. 18, 2024, 2:55 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2022-25774 - XSS in Notifications via saving Dashboards

Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards.

๐Ÿ“… Published: Sept. 18, 2024, 2:54 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2024, 11:21 p.m.

9.4

CVSS4.0

CVE-2024-6877 - Reflected XSS in Eliz Software's Panel

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.

๐Ÿ“… Published: Sept. 18, 2024, 2:51 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 6:57 p.m.

9.8

CVSS3.1

CVE-2024-5960 - Plaintext Storage of a Password in Eliz Software's Panel

Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.

๐Ÿ“… Published: Sept. 18, 2024, 2:49 p.m. ๐Ÿ”„ Last Modified: Sept. 24, 2025, 2:08 p.m.

7.2

CVSS3.1

CVE-2022-25769 - Improper regex in htaccess file

ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.

๐Ÿ“… Published: Sept. 18, 2024, 2:47 p.m. ๐Ÿ”„ Last Modified: Sept. 20, 2024, 12:30 p.m.

9.3

CVSS4.0

CVE-2024-5959 - Stored XSS in Eliz Software's Panel

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.

๐Ÿ“… Published: Sept. 18, 2024, 2:44 p.m. ๐Ÿ”„ Last Modified: Sept. 26, 2024, 1:39 p.m.
Total resulsts: 349182
Page 8512 of 34,919
ยซ previous page ยป next page
Filters