CVE-2024-47050: Acquia Mautic

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.

Affected products

  • Acquia Mautic: from 2.6.0, before 4.4.13 (fixed in 4.4.13); from 5.0.0, before 5.1.1 (fixed in 5.1.1)

Published 2024-09-18. Last modified 2026-06-17.