Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mantisbt MEDIUM 6.1
CVE-2026-33517

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), improper escaping of its name…

Patch available
Fix from $1,600 2026-03-23
Mantisbt MEDIUM 6.1
CVE-2026-33548

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (…

Patch available
Fix from $1,600 2026-03-23
Mantisbt CRITICAL 9.8
CVE-2026-30849

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authenti…

Fix: 2.28.1+
Fix from $2,300 2026-03-23
Mantisbt MEDIUM 5.4
CVE-2025-55155

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail a…

Fix: 2.27.2+
Fix from $1,600 2025-11-04
Mantisbt CRITICAL 9.1
CVE-2025-47776

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===) comparison in the authentic…

Fix: 2.27.2+
Fix from $2,300 2025-11-04
Mantisbt HIGH 7.5
CVE-2025-46556

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs b…

Fix: 2.27.2+
Fix from $1,950 2025-11-04
Mantisbt MEDIUM 6.5
CVE-2024-45792

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve inf…

Fix: 2.26.4+
Fix from $1,600 2024-09-30
Mantisbt MEDIUM 5.3
CVE-2024-34080

MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have…

Fix: 2.26.2+
Fix from $1,600 2024-05-14
Mantisbt HIGH 7.3
CVE-2024-34077

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an a…

Fix: 2.26.2+
Fix from $1,950 2024-05-14
Mantisbt HIGH 8.3
CVE-2024-23830

MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hija…

Fix: 2.26.1+
Fix from $1,950 2024-02-20
Linked Custom Fields MEDIUM 6.1
CVE-2023-49802

The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1,…

Fix: 2.0.1+
Fix from $1,600 2023-12-11
Mantisbt MEDIUM 5.4
CVE-2022-33910

An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or a…

Fix: 2.25.5+
Fix from $1,600 2022-06-24
Mantisbt MEDIUM 6.1
CVE-2022-28508EPSS 5%

An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to in…

Fix: 2.25.2+
Fix from $1,600 2022-05-04
Mantisbt HIGH 7.8
CVE-2021-43257

Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to…

Fix: 2.25.3+
Fix from $1,950 2022-04-14
Mantisbt MEDIUM 6.1
CVE-2022-26144

An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in ma…

Fix: 2.25.3+
Fix from $1,600 2022-04-13
Mantisbt MEDIUM 6.1
CVE-2021-33557

An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attack…

Fix: 2.25.2+
Fix from $1,600 2021-06-17
Mantisbt HIGH 8.1
CVE-2009-20001

An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., t…

Fix: 2.24.5+
Fix from $1,950 2021-03-07
Mantisbt MEDIUM 6.1
CVE-2020-35571

An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is n…

Fix: after 2.24.3
Fix from $1,600 2021-02-22
Mantisbt MEDIUM 6.5
CVE-2020-29604

An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues…

Fix: 2.24.4+
Fix from $1,600 2021-01-29
Source Integration MEDIUM 5.3
CVE-2020-36192

An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the Summary field of private Issue…

Fix: 2.4.1+
Fix from $1,600 2021-01-18
Mantisbt MEDIUM 6.5
CVE-2020-28413

In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.

No fix yet
Fix from $1,600 2020-12-30
Mantisbt HIGH 7.5
CVE-2020-35849

An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view th…

Fix: 2.24.4+
Fix from $1,950 2020-12-30
Mantisbt MEDIUM 5.4
CVE-2020-16266

An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML i…

Fix: 2.24.2+
Fix from $1,600 2020-08-12
Mantisbt MEDIUM 6.1
CVE-2019-15539

The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing ex…

Fix: 2.21.3+
Fix from $1,600 2020-03-19
Source Integration MEDIUM 6.1
CVE-2020-8981

A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_d…

Fix: 1.6.2 / 2.3.1+
Fix from $1,600 2020-02-13
Mantisbt MEDIUM 6.1
CVE-2009-2802

MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting…

Fix: 1.2.2+
Fix from $1,600 2019-11-09
Mantisbt MEDIUM 5.4
CVE-2013-1932

A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated us…

Mitigation only
Fix from $1,600 2019-10-31
Mantisbt HIGH 7.2
CVE-2019-15715EPSS 30%

MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.

Fix: 1.3.20 / 2.22.1+
Fix from $1,950 2019-10-09
Mantisbt CRITICAL 9.6
CVE-2019-15074

The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbi…

Fix: after 2.21.1
Fix from $2,300 2019-08-21
Mantisbt MEDIUM 6.5
CVE-2018-9839

An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any u…

Fix: after 1.3.14
Fix from $1,600 2019-06-06