Home/Product/matomo
Product

matomo

26 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-4415
< 1.3.2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cros
4.8MEDIUM
CVE-2023-6923
< 5.0.1
The Matomo Analytics - Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via
6.1MEDIUM
CVE-2017-20175
>= 2.4.0 and < 2.4.3
A vulnerability classified as problematic has been found in DaSchTour matomo-mediawiki-extension up to 2.4.2 on MediaWiki. This af
2.6LOW
CVE-2022-33156
< 1.3.2
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
6.1MEDIUM
CVE-2020-29578
all versions
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the P
9.8CRITICAL
CVE-2013-0195
< 1.10.1
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified v
6.1MEDIUM
CVE-2013-0194
< 1.10.1
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified v
6.1MEDIUM
CVE-2013-0193
< 1.10.1
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified v
6.1MEDIUM
CVE-2019-12215
all versions
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the f
4.3MEDIUM
CVE-2015-7816
<= 2.14.3
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP
CVE-2015-7815
<= 2.14.3
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and
CVE-2013-2633
<= 1.10.1
Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attac
CVE-2013-1844
<= 1.10.1
Cross-site scripting (XSS) vulnerability in Piwik before 1.11 allows remote attackers to inject arbitrary web script or HTML via u
CVE-2012-4541
<= 1.8.4
Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via un
CVE-2011-4941
all versions
Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via
CVE-2011-3791
all versions
Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installat
CVE-2011-0401
<= 1.0
Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cau
CVE-2011-0400
<= 1.0
Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for
CVE-2011-0399
<= 1.0
Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it ea
CVE-2011-0398
<= 1.0
The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attack
CVE-2011-0004
<= 1.0
Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or H
CVE-2010-2786
all versions
Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly
CVE-2010-1453
all versions
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrar
CVE-2009-4137
all versions
The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before c
CVE-2009-4140
all versions
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used
CVE-2009-1085
<= 0.2.32
Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote att
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin