Matomo
25 known vulnerabilities
Top Products
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO a
The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scri
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems u
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to disc
Frequently Asked Questions
How many CVEs affect Matomo?
Matomo has 25 CVE records in our database, including 1 critical and 4 high severity vulnerabilities.
What are the most severe Matomo vulnerabilities?
Matomo has 1 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Matomo vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Matomo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Matomo Vulnerabilities
CyberStrike scans your infrastructure for Matomo vulnerabilities and provides real-time remediation guidance.
Get Started