CVE-2020-35125: Acquia Mautic

Critical severity, CVSS 9.6. EPSS: 2.7% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).

Affected products

  • Acquia Mautic: before 2.16.5 (fixed in 2.16.5); from 3.0.0, before 3.2.4 (fixed in 3.2.4)

Published 2021-02-09. Last modified 2026-06-17.