Mautic · Mautic · CVE-2026-9809
**Name of the Vulnerable Software and Affected Versions**
Mautic versions prior to 7.1.2
**Description**
A stored Cross-Site Scripting (XSS) issue exists in the Projects component. When administrative detail views for campaigns, emails, or forms display project tags and popovers, user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can inject malicious script payloads. When an administrator hovers over a tag associated with a compromised project, the script executes in their browser session, potentially allowing the attacker to perform administrative actions, change system configurations, or exfiltrate sensitive data.
**Recommendations**
Update to version 7.1.2.
Restrict project creation and modification permissions to trusted administrative users.