Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. mautic/core
  4. ›
  5. CVE-2026-9811

CVE-2026-9811: Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector

July 2, 2026

A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project’s name.

References

  • github.com/advisories/GHSA-5hvg-w58j-545m
  • github.com/mautic/mautic/security/advisories/GHSA-5hvg-w58j-545m
  • nvd.nist.gov/vuln/detail/CVE-2026-9811

Code Behaviors & Features

Detect and mitigate CVE-2026-9811 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.0.0 before 7.1.2

Fixed versions

  • 7.1.2

Solution

Upgrade to version 7.1.2 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/mautic/core/CVE-2026-9811.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 13 Jul 2026 00:18:50 +0000.