Cross-site scripting in Mautic - CVE-2025-9823
Published: May 25, 2026
Mautic
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the context of another user's session.
The vulnerability exists due to cross-site scripting in the /s/ajax?action=lead:addLeadTags endpoint when reflecting user-supplied input in the "Tags" input field. A remote attacker can send a specially crafted request to execute arbitrary JavaScript in the context of another user's session.