Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-9811 is a stored Cross-Site Scripting (XSS) vulnerability in Mautic version 7.0.0. It occurs in the project selector component where project names returned via AJAX are not properly sanitized before being injected into the DOM. An authenticated user with project creation permissions can store malicious scripts in project names, which execute when another administrative user opens an entity editor containing the project selector. This can lead to session hijacking or unauthorized access to organizational data within the dashboard. Join the discussion | CVE Database V5 | 05/29/2026, 10:41:29 UTC Added: 05/29/2026, 11:48:46 UTC |
0 CVE-2026-9809 is a stored Cross-Site Scripting (XSS) vulnerability in Mautic version 7.0.0 affecting the Projects component. It occurs when project names supplied by authenticated users with project creation or editing permissions are rendered without proper sanitization in administrative detail views. This allows malicious scripts to execute in the browser context of administrative users who view or hover over compromised project tags, potentially enabling unauthorized administrative actions or data exfiltration. Join the discussion | CVE Database V5 | 05/29/2026, 10:36:38 UTC Added: 05/29/2026, 11:48:42 UTC |
0 CVE-2026-9808 is an authorization bypass vulnerability in Mautic 7.0.0 API v2 endpoints. Roles with owner-scope restrictions such as 'viewown' or 'editown' are not properly enforced, allowing low-privilege authenticated API users to access or modify resources owned by other users. This vulnerability has a high severity with a CVSS score of 7.1. Join the discussion | CVE Database V5 | 05/29/2026, 10:30:23 UTC Added: 05/29/2026, 11:48:42 UTC |
0 CVE-2026-9559 is a critical path traversal vulnerability in Mautic version 7.0.0 affecting the campaign import feature. It allows an authenticated user with campaign import privileges to write arbitrary PHP files outside the intended temporary directories by exploiting improper validation of ZIP file extraction paths. This can lead to remote code execution under the web server user context. Join the discussion | CVE Database V5 | 05/29/2026, 10:19:48 UTC Added: 05/29/2026, 11:48:42 UTC |
0 CVE-2026-9558 is a critical Server-Side Template Injection (SSTI) vulnerability in Mautic's theme engine. It allows authenticated users with theme creation or upload permissions to execute arbitrary code on the hosting server or access restricted system files. The vulnerability arises because the platform renders uploaded Twig templates without sandboxing or strict function restrictions. This can lead to remote code execution and full compromise of confidentiality, integrity, and availability of the affected system. Join the discussion | CVE Database V5 | 05/29/2026, 10:01:36 UTC Added: 05/29/2026, 10:33:34 UTC |
CVE-2026-9557 is a Server-Side Request Forgery (SSRF) vulnerability in Mautic's Focus component. It allows an authenticated user to cause the hosting server to make HTTP requests to arbitrary internal or external destinations due to insufficient validation of user-supplied URLs. This can enable internal network reconnaissance or interaction with unintended network resources. The vulnerability affects specific versions 4.0.0, 5.0.0, 6.0.0, and 7.0.0 of Mautic. The CVSS score is 6.4, indicating a medium severity level. No official patch or remediation guidance is currently available, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 05/29/2026, 09:38:40 UTC Added: 05/29/2026, 10:33:34 UTC |
0 CVE-2026-4776 is an SQL injection vulnerability in Mautic's API contact filtering mechanism. It arises from insufficient recursive sanitization of nested query parameters, allowing an authenticated API user to bypass input filtering and inject arbitrary SQL commands. The vulnerability affects specific versions of Mautic. The CVSS score is 7.1, indicating a high severity. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 05/29/2026, 06:58:24 UTC Added: 05/29/2026, 07:48:34 UTC |
Showing 1 to 7 of 7 results