CVE-2026-9811 | Mautic up to 7.1.1 Project Selector cross site scripting (GHSA-5hvg-w58j-545m / WID-SEC-2026-1724)
ID: 59e09b07-b8d7-5645-8ecf-70329169b8a4
STIX ID: report--59e09b07-b8d7-5645-8ecf-70329169b8a4
Feed Name: VulDB Recent Entries
Threat Score
Stored Cross-Site Scripting (CVE-2026-9811) was found in Mautic up to 7.1.1 within the Project Selector component: an authenticated user with project-creation rights can persist malicious JavaScript in project names that executes in administrators' browsers when the selector is rendered. No public exploit is available; upgrade to Mautic 7.1.2 is recommended to remediate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
