CVE-2018-8092Disclosure(mautic / mautic)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mautic mautic systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Mautic before 2.13.0 allows CSV injection.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1236

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mautic

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mautic

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-02: 1Active Exploitation · 2026-08-02: 1Patch / Workaround · 2026-08-02: 1Technical Details · 2026-08-02: 108-02
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Cloud Geeks@cloudgeeks_au
    Disclosure

    Mautic self-hosters: CVE-2018-8092 is CVSS 9.8 (critical). Attack: formula injected via contact form, staff exports CSV, opens in Excel, formula runs. Fix: upgrade to Mautic 2.13.0+. https://insights.cloudgeeks.com.au/blog/mautic-csv-injection-cve-2018-8092/ https://t.co/qS31S5qxxI

    Post summary

    The post announces CVE‑2018‑8092 as a critical flaw in Mautic that allows attackers to inject executable formulas through the contact form; it cites the CVSS score and urges an upgrade to Mautic 2.13.0+ to remediate the issue.

    0000026
    629 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmauticmautic---

Explore more