<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Matomo</title>
  <link>https://cvedaily.com/pages/tags/matomo.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/matomo.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Matomo</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2025-58630 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58630</guid>
    <pubDate>Wed, 03 Sep 2025 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58630</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer Simple Matomo Tracking Code simple-matomo-tracking-code allows Stored XSS.This issue affects Simple Matomo Tracking Code: from n/a through <= 1.1.0.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34104 – An authenticated remote code execution vulnerability exists in Piwik (now Matomo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34104</guid>
    <pubDate>Tue, 15 Jul 2025 13:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34104</strong></p>
  <p>An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disa…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-31680 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31680</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-31680</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38766 – Cross-Site Request Forgery (CSRF) vulnerability in matomoteam Matomo Analytics m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38766</guid>
    <pubDate>Thu, 02 Jan 2025 12:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38766</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in matomoteam Matomo Analytics matomo allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through <= 5.1.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6923 – The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6923</guid>
    <pubDate>Thu, 29 Feb 2024 01:42:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6923</strong></p>
  <p>The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite parameter in all versions up to, and including, 4.15.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a use…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4774 – The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Store...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4774</guid>
    <pubDate>Fri, 22 Sep 2023 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4774</strong></p>
  <p>The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik' shortcode in versions up to, and including, 1.0.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages t…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-33211 – Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33211</guid>
    <pubDate>Sun, 28 May 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-33211</strong></p>
  <p>Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 versions.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23659 – Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension &lt;= 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23659</guid>
    <pubDate>Thu, 23 Feb 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23659</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2017-20175 – A vulnerability classified as problematic has been found in DaSchTour matomo-med...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-20175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-20175</guid>
    <pubDate>Sun, 05 Feb 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2017-20175</strong></p>
  <p>A vulnerability classified as problematic has been found in DaSchTour matomo-mediawiki-extension up to 2.4.2 on MediaWiki. This affects an unknown part of the file Piwik.hooks.php of the component Username Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult.…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-20175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-33156 – The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33156</guid>
    <pubDate>Tue, 12 Jul 2022 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-33156</strong></p>
  <p>The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12215 – A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12215</guid>
    <pubDate>Mon, 20 May 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12215</strong></p>
  <p>A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilitie…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12215">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
