Mautic v7.2.0 Release Notes

Release Date: 2026-06-02 // 6 days ago
  • ๐Ÿš€ Welcome to Mautic 7.2.0 Release Candidate: Lynx Edition

    ๐Ÿš€ Mautic 7.2 is here! Today we are excited to announce the release of Mautic 7.2 Release Candidate.

    ๐Ÿš€ โš ๏ธ This is a Release Candidate pre-release and should only be used for testing purposes. DO NOT use this in a production environment.

    What's Changed

    ๐Ÿ”จ ๐Ÿ”ง Refactoring

    ๐Ÿค– DevOps
    โฌ†๏ธ Dependencies
    ๐Ÿง‘โ€๐Ÿ’ป Developer experience
    ๐Ÿš€ Campaigns

    โœจ Features and enhancements

    ๐Ÿ— ๐Ÿ‡ GrapesJS Builder
    ๐Ÿ’ป API
    • โœจ Enhance tag search, api and ui, to match descriptions as well. by @shinde-rahul in #16003
    ๐ŸŒ Landing pages
    ๐Ÿ‘ฃ Tracking
    • โ†” Integrate matomo-org/device-detector library for Bot identification by @escopecz in #15870
    • โž• Add global defaults for preference center and UTM tracking parameters by @msoukhomlinov in #15905
    ๐Ÿฑ ๐Ÿ“Assets
    ๐Ÿ“Š Reports
    ๐Ÿ‘ฅ Contacts
    • โž• Added LeadList::getDeleted() method by @fedys in #16093
    • ๐Ÿ‘Œ Improve contact timeline readability with intuitive date grouping by @kuzmany in #15329
    • ๐ŸŒฒ Option to skip contact last active logging by @fedys in #16080
    ๐Ÿ“Œ Dashboards
    • ๐Ÿ›  Fix upcoming Emails widget on Dashboard fails to load due to query timeout by @rohitpavaskar in #16101
    ๐Ÿค– DevOps
    • โž• Added new command which will process the stuck campaign events by @rohitpavaskar in #15310
    ๐ŸŽจ User Experience / User Interface
    • โž• Add modal to help users decide between field and tag with visual tiles and FAQ by @andersonjeccel in #15296
    • ๐Ÿ— [UXUI-243] Hold space bar to drag view in campaign builder by @andersonjeccel in #15821
    ๐ŸŒ Segments
    • ๐Ÿ‘ Segment filters support relative date up hours by @escopecz in #16135
    ๐Ÿ’Œ Email
    ๐ŸŽ ๐Ÿš„ Performance and optimization
    • ๐Ÿ“‡ Reduce Import Memory/Time: Cache Default Field Metadata by @patrykgruszka in #15959
    • โšก๏ธ Optimize excluded segments query to prevent full table scans by @patrykgruszka in #15950
    ๐Ÿข Companies

    ๐Ÿ› Bugs

    ๐ŸŒ Segments
    • Prevent deletion of segment while used in a campaign by @escopecz in #16013
    ๐Ÿ”Œ ๐ŸŒฑ Plugin support
    • Remove skip_if_exist option from plugins (custom object) by @escopecz in #16008
    ๐Ÿ’Œ Email
    • ๐Ÿ›  Fix email signature missing when added by {signature} token by @escopecz in #15931
    ๐ŸŽจ User Experience / User Interface
    ๐ŸŒ Landing pages
    ๐Ÿ“Š Reports
    ๐Ÿ‘ฅ Contacts
    ๐Ÿ”Œ ๐ŸŒฑ Plugin support
    ๐Ÿš€ Campaigns
    ๐Ÿ— ๐Ÿ‡ GrapesJS Builder
    • ๐Ÿ›  Fix CKEditor license-key-missing in GrapesJS HTML email builder by @Copilot in #16191
    • ๐Ÿ›  Fix TypeError when MJML theme contains <mj-preview> tag by @patrykgruszka in #16106
    ๐Ÿ‘ฃ Tracking
    • Prevent page_hits with null data from being persisted to the db. by @escopecz in #16130

    ๐Ÿ†• New Contributors

    Full Changelog : 7.1.2...7.2.0-rc

    SHA1(7.2.0-rc.zip)= 60a0428753a92500424a23d071c045085c8f2304
    โšก๏ธ SHA1(7.2.0-rc-update.zip)= 40c53bd16690aba1c014b1be552a8843156586c1


Previous changes from v7.1.2

  • Announcing Mautic 7.1.2: Aludra Edition

    ๐Ÿš€ ๐Ÿ”’ Security Release

    ๐Ÿš€ This release addresses several security vulnerabilities. We strongly advise updating your installation at your earliest convenience after performing a full backup and testing the upgrade in a staging environment.

    ๐Ÿ”’ ๐Ÿ”’ Security Fixes

    • CVE-2026-4776: SQL Injection in API Contact Filtering

    • CVE-2026-9557: SSRF in the Mautic Focus Component

    • CVE-2026-9558: Server-Side Template Injection (SSTI) in Theme Templates

    • CVE-2026-9559: Path Traversal via Campaign Import

    • CVE-2026-9808: Authorization Bypass in API v2 Endpoints

    • CVE-2026-9809: Stored Cross-Site Scripting (XSS) in Projects Component

    • CVE-2026-9811: Stored Cross-Site Scripting (XSS) in Project Option Selector

    โšก๏ธ ๐Ÿค– DevOps Updates

    • โšก๏ธ Update vulnerable Composer dependencies for 6.0 security phase (by @escopecz).

    What's Changed

    ๐Ÿ› Bugs

    • โฌ†๏ธ Bumping CK editor libraries by @escopecz in #16074
    • Handling adding points to deleted contacts by @escopecz in #16073
    • โœ… Register mautic:phpunit:config command in test environment only by @fedys in #16104
    • ๐Ÿ›  fix(grapesjs): avoid MJML reparse in HTML mode in source editor by @fujijin in #15971
    • โœ… Stabilizing a flaky test by @escopecz in #16134

    ๐Ÿ†• New Contributors

    ๐Ÿš€ ๐Ÿ’ก Release Team & Sponsors

    ๐Ÿš€ This release was made possible through the dedicated efforts of our community and supporters:

    SHA1(7.1.2.zip)= 6da6aa5e2ad41d3f1a1f07788d05fd185e2e0fb3
    โšก๏ธ SHA1(7.1.2-update.zip)= 584841094031c93229a9ebf144f92c34e35ffd26