CVE-2024-47058: Acquia Mautic

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.

Affected products

  • Acquia Mautic: from 1.0.0, before 4.4.13 (fixed in 4.4.13); from 5.0.0, before 5.1.1 (fixed in 5.1.1)

Published 2024-09-18. Last modified 2026-06-17.