CVE-2026-9809
Deferred Deferred - Pending Action
Stored XSS in Mautic Projects Component

Publication date: 2026-05-29

Last updated on: 2026-05-29

Assigner: Mautic

Description
A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. When an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-29
Last Modified
2026-05-29
Generated
2026-06-19
AI Q&A
2026-05-29
EPSS Evaluated
2026-06-18
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
mautic mautic 7.1.2
mautic mautic to 7.1.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a stored Cross-Site Scripting (XSS) issue found in the Projects component of Mautic 7. It occurs because user-supplied project names are displayed without proper sanitization on administrative detail views such as campaigns, emails, or forms. An authenticated user who has permission to create or edit projects can inject malicious script payloads into project names.

When an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within their browser session. This allows the attacker to run malicious code in the context of the victim's session.

Impact Analysis

The impact of this vulnerability includes the potential for an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data. Since the malicious script runs in the context of an administrative user's browser session, it can lead to unauthorized changes and data breaches.

Detection Guidance

The vulnerability involves stored Cross-Site Scripting (XSS) in project names rendered without proper sanitization in Mautic 7's Projects component. Detection involves identifying if any project names contain malicious script payloads that execute when hovered over in administrative views.

Since the vulnerability requires an authenticated user with project creation or editing permissions to inject scripts, detection can focus on reviewing project names for suspicious or unexpected script tags or payloads.

There are no specific commands provided in the available resources to detect this vulnerability on your system or network.

Mitigation Strategies

The vulnerability has been patched in Mautic version 7.1.2. The primary immediate mitigation is to upgrade to this patched version.

If upgrading immediately is not possible, restrict project creation and modification permissions to trusted users only to prevent malicious script injection.

Compliance Impact

This vulnerability allows an attacker to execute malicious scripts within an administrative user's browser session, potentially enabling unauthorized administrative actions, alteration of system configurations, or exfiltration of sensitive data.

Such unauthorized access and potential data exfiltration could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require safeguarding sensitive data and ensuring system integrity.

Therefore, if exploited, this vulnerability could compromise the confidentiality and integrity of sensitive information, impacting compliance with these common standards and regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9809. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart