Stored Cross-Site Scripting Vulnerability in Mautic by Mautic
CVE-2026-9809
What is CVE-2026-9809?
In Mautic 7, a stored Cross-Site Scripting (XSS) vulnerability exists within the Projects component. This flaw arises due to improper sanitization of user-supplied project names displayed in administrative detail views, such as campaigns, emails, or forms. When an authenticated user, who has permission to create or edit projects, inputs a compromised project name, injected scripts can execute when administrative users interact with affected entities. This manipulation allows attackers to perform unintended administrative actions, modify system configurations, or extract sensitive information from the vulnerable system.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
