Stored Cross-Site Scripting Vulnerability in Mautic by Mautic
CVE-2026-9809
7.6HIGH
What is CVE-2026-9809?
In Mautic 7, a stored Cross-Site Scripting (XSS) vulnerability exists within the Projects component. This flaw arises due to improper sanitization of user-supplied project names displayed in administrative detail views, such as campaigns, emails, or forms. When an authenticated user, who has permission to create or edit projects, inputs a compromised project name, injected scripts can execute when administrative users interact with affected entities. This manipulation allows attackers to perform unintended administrative actions, modify system configurations, or extract sensitive information from the vulnerable system.
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
@34selen
John Linhart (@escopecz)
Patryk Gruszka (@patrykgruszka)
Leuchtfeuer Digital Marketing (@Leuchtfeuer)
