PT-2026-44823 · Mautic · Mautic

·

CVE-2026-9811

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mautic versions prior to 7.1.2
Description A stored Cross-Site Scripting (XSS) issue exists in the project selector component. The application fails to sanitize project names returned via AJAX before injecting them into the Document Object Model (DOM) as option fields. An authenticated user with project creation permissions can store a malicious script payload in a project name. When an administrative user opens an entity editor containing the project selector, the script executes in their browser session, potentially leading to session hijacking, unauthorized state coordination, or unauthorized access to organizational data.
Recommendations Update to version 7.1.2. Restrict project creation and modification permissions to trusted administrative users.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9811
GHSA-5HVG-W58J-545M

Affected Products

Mautic