Записи acquia
43 опубликованных записей вендора acquia.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 83,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
43 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2022-25772Эксплойта нет | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executableacquia · mautic · CWE-79 | Средняя6,1 | — | 62,3 % | 20 июн. 2022 г. |
40В плане | CVE-2024-47051Proof of concept | Remote Code Execution & File Deletion in Asset Uploadsacquia · mautic · CWE-23 | Критическая9,9 | — | 1,8 % | 26 февр. 2025 г. |
39Наблюдать | CVE-2020-35125Эксплойта нет | A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScacquia · mautic · CWE-79 | Критическая9,6 | — | 2,7 % | 9 февр. 2021 г. |
39Наблюдать | CVE-2020-35124Эксплойта нет | A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaSacquia · mautic · CWE-79 | Критическая9,6 | — | 2,4 % | 28 янв. 2021 г. |
36Наблюдать | CVE-2020-35128Эксплойта нет | Mautic before 3.2.4 is affected by stored XSS.acquia · mautic · CWE-79 | Критическая9,0 | — | 1,7 % | 19 янв. 2021 г. |
36Наблюдать | CVE-2021-27915Эксплойта нет | XSS Cross-site Scripting Stored (XSS) - Description fieldacquia · mautic · CWE-80 | Критическая9,0 | — | 0,6 % | 17 сент. 2024 г. |
36Наблюдать | CVE-2022-25769Эксплойта нет | Improper regex in htaccess fileacquia · mautic · CWE-1284 | Критическая9,1 | — | 0,5 % | 18 сент. 2024 г. |
35Наблюдать | CVE-2017-8874Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for acquia · mautic · CWE-352 | Высокая8,8 | — | 0,8 % | 10 мая 2017 г. |
35Наблюдать | CVE-2026-3105Эксплойта нет | SQL Injection in Contact Activity API Sortingacquia · mautic · CWE-89 | Высокая8,8 | — | 0,4 % | 24 февр. 2026 г. |
32Наблюдать | CVE-2017-1000489Эксплойта нет | Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email addressmautic · mautic · CWE-287 | Высокая8,1 | — | 1,1 % | 3 янв. 2018 г. |
32Наблюдать | CVE-2021-27916Эксплойта нет | Relative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)acquia · mautic · CWE-22 | Высокая8,1 | — | 0,8 % | 17 сент. 2024 г. |
32Наблюдать | CVE-2025-14472Эксплойта нет | Acquia Content Hub - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2025-125acquia · acquia content hub · CWE-352 | Высокая8,1 | — | 0,2 % | 28 янв. 2026 г. |
30Наблюдать | CVE-2015-8754Эксплойта нет | The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacquia · mollom · CWE-264 | Высокая7,5 | — | 1,3 % | 8 янв. 2016 г. |
30Наблюдать | CVE-2024-47053Эксплойта нет | Improper Authorization in Reporting APIacquia · mautic · CWE-285 | Высокая7,7 | — | 0,7 % | 26 февр. 2025 г. |
30Наблюдать | CVE-2025-9954Эксплойта нет | Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105acquia · dam · CWE-862 | Высокая7,5 | — | 0,3 % | 29 окт. 2025 г. |
30Наблюдать | CVE-2022-25770Эксплойта нет | Insufficient authentication in upgrade flowacquia · mautic · CWE-306 | Высокая7,5 | — | 0,3 % | 18 сент. 2024 г. |
28Наблюдать | CVE-2022-25775Эксплойта нет | SQL Injection in dynamic Reportsacquia · mautic · CWE-89 | Высокая7,2 | — | 0,6 % | 18 сент. 2024 г. |
26Наблюдать | CVE-2017-1000490Эксплойта нет | Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanmautic · mautic · CWE-22 | Средняя6,5 | — | 1,4 % | 3 янв. 2018 г. |
26Наблюдать | CVE-2022-25777Эксплойта нет | Server-Side Request Forgery in Asset sectionacquia · mautic · CWE-918 | Средняя6,5 | — | 0,4 % | 18 сент. 2024 г. |
26Наблюдать | CVE-2022-25776Эксплойта нет | Sensitive Data Exposure due to inadequate user permission settingsacquia · mautic · CWE-276 | Средняя6,5 | — | 0,4 % | 18 сент. 2024 г. |
26Наблюдать | CVE-2022-25768Эксплойта нет | Improper Access Control in UI upgrade processacquia · mautic · CWE-287 | Средняя6,5 | — | 0,3 % | 18 сент. 2024 г. |
25Наблюдать | CVE-2021-27909Proof of concept | XSS vulnerability on password reset pageacquia · mautic · CWE-79 | Средняя6,1 | — | 4,1 % | 30 авг. 2021 г. |
24Наблюдать | CVE-2018-11198Эксплойта нет | An issue was discovered in Mautic 2.13.1.acquia · mautic · CWE-79 | Средняя6,1 | — | 0,9 % | 6 сент. 2019 г. |
24Наблюдать | CVE-2017-1000488Эксплойта нет | Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parametersmautic · mautic · CWE-79 | Средняя6,1 | — | 0,8 % | 3 янв. 2018 г. |
24Наблюдать | CVE-2018-11200Эксплойта нет | An issue was discovered in Mautic 2.13.1.acquia · mautic · CWE-79 | Средняя6,1 | — | 0,8 % | 20 сент. 2019 г. |
- CVE-2022-2577243В плане
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable
СредняяCVSS 6,1Эксплойта нетEPSS 62 %acquia · mautic20 июн. 2022 г.
- CVE-2024-4705140В плане
Remote Code Execution & File Deletion in Asset Uploads
КритическаяCVSS 9,9Proof of conceptEPSS 2 %acquia · mautic26 февр. 2025 г.
- CVE-2020-3512539Наблюдать
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaSc
КритическаяCVSS 9,6Эксплойта нетEPSS 3 %acquia · mautic9 февр. 2021 г.
- CVE-2020-3512439Наблюдать
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaS
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %acquia · mautic28 янв. 2021 г.
- CVE-2020-3512836Наблюдать
Mautic before 3.2.4 is affected by stored XSS.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %acquia · mautic19 янв. 2021 г.
- CVE-2021-2791536Наблюдать
XSS Cross-site Scripting Stored (XSS) - Description field
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %acquia · mautic17 сент. 2024 г.
- CVE-2022-2576936Наблюдать
Improper regex in htaccess file
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %acquia · mautic18 сент. 2024 г.
- CVE-2017-887435Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %acquia · mautic10 мая 2017 г.
- CVE-2026-310535Наблюдать
SQL Injection in Contact Activity API Sorting
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %acquia · mautic24 февр. 2026 г.
- CVE-2017-100048932Наблюдать
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %mautic · mautic3 янв. 2018 г.
- CVE-2021-2791632Наблюдать
Relative Path Traversal / Arbitrary File Deletion in Mautic (GrapesJS Builder)
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %acquia · mautic17 сент. 2024 г.
- CVE-2025-1447232Наблюдать
Acquia Content Hub - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2025-125
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %acquia · acquia content hub28 янв. 2026 г.
- CVE-2015-875430Наблюдать
The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom bl
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %acquia · mollom8 янв. 2016 г.
- CVE-2024-4705330Наблюдать
Improper Authorization in Reporting API
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %acquia · mautic26 февр. 2025 г.
- CVE-2025-995430Наблюдать
Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %acquia · dam29 окт. 2025 г.
- CVE-2022-2577030Наблюдать
Insufficient authentication in upgrade flow
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %acquia · mautic18 сент. 2024 г.
- CVE-2022-2577528Наблюдать
SQL Injection in dynamic Reports
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %acquia · mautic18 сент. 2024 г.
- CVE-2017-100049026Наблюдать
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Fileman
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mautic · mautic3 янв. 2018 г.
- CVE-2022-2577726Наблюдать
Server-Side Request Forgery in Asset section
СредняяCVSS 6,5Эксплойта нетEPSS 0 %acquia · mautic18 сент. 2024 г.
- CVE-2022-2577626Наблюдать
Sensitive Data Exposure due to inadequate user permission settings
СредняяCVSS 6,5Эксплойта нетEPSS 0 %acquia · mautic18 сент. 2024 г.
- CVE-2022-2576826Наблюдать
Improper Access Control in UI upgrade process
СредняяCVSS 6,5Эксплойта нетEPSS 0 %acquia · mautic18 сент. 2024 г.
- CVE-2021-2790925Наблюдать
XSS vulnerability on password reset page
СредняяCVSS 6,1Proof of conceptEPSS 4 %acquia · mautic30 авг. 2021 г.
- CVE-2018-1119824Наблюдать
An issue was discovered in Mautic 2.13.1.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %acquia · mautic6 сент. 2019 г.
- CVE-2017-100048824Наблюдать
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters
СредняяCVSS 6,1Эксплойта нетEPSS 1 %mautic · mautic3 янв. 2018 г.
- CVE-2018-1120024Наблюдать
An issue was discovered in Mautic 2.13.1.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %acquia · mautic20 сент. 2019 г.