Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mantisbt MEDIUM 5.4
CVE-2018-17782

A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attacke…

Fix: after 2.17.1
Fix from $1,600 2018-10-30
Mantisbt MEDIUM 5.4
CVE-2018-17783

A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attac…

Fix: after 2.17.1
Fix from $1,600 2018-10-30
Source Integration MEDIUM 6.1
CVE-2018-16362

An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site scripting (XSS) vulnerability i…

Fix: 1.5.9 / 2.1.5+
Fix from $1,600 2018-09-02
Mantisbt MEDIUM 6.1
CVE-2018-13055

A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers …

Fix: after 2.15.0
Fix from $1,600 2018-08-03
Mantisbt MEDIUM 6.1
CVE-2018-14504

An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter …

Fix: after 2.15.0
Fix from $1,600 2018-08-03
Mantisbt MEDIUM 5.3
CVE-2018-6526

view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parame…

Fix: after 2.10.0
Fix from $1,600 2018-02-02
Mantisbt HIGH 7.5
CVE-2014-9624

CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

Fix: after 1.2.18
Fix from $1,950 2017-09-12
Mantisbt MEDIUM 6.1
CVE-2015-2046

Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20.

Patch available
Fix from $1,600 2017-08-28
Mantisbt MEDIUM 6.5
CVE-2014-9701

Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web scri…

Fix: after 1.2.18
Fix from $1,600 2017-08-09
Mantisbt MEDIUM 6.1
CVE-2017-12061

An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under user control in the MantisBT in…

Fix: 1.3.12 / 2.5.2+
Fix from $1,600 2017-08-01
Mantisbt MEDIUM 6.1
CVE-2017-12062

An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Ma…

Patch available
Fix from $1,600 2017-08-01
Mantisbt MEDIUM 5.3
CVE-2015-5059

The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc_threshold) is set to ANYBODY…

Fix: after 1.2.19
Fix from $1,600 2017-08-01
Mantisbt MEDIUM 6.5
CVE-2017-7620

MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpret…

Fix: after 1.3.10
Fix from $1,600 2017-05-21
Mantisbt MEDIUM 6.1
CVE-2017-7897

A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x before 2.3.2) Timeline include page, used in My View (my_view_page.php) and User In…

Patch available
Fix from $1,600 2017-04-18
Mantisbt HIGH 8.8
CVE-2017-7615EPSS 91%

MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

Fix: after 2.3.0
Fix from $1,950 2017-04-16
Mantisbt MEDIUM 6.1
CVE-2017-7222

A cross-site scripting (XSS) vulnerability in MantisBT before 2.1.1 allows remote attackers to inject arbitrary HTML or JavaScript (if MantisBT's CSP…

Fix: after 2.1.0
Fix from $1,600 2017-03-22
Source Integration MEDIUM 6.1
CVE-2017-6958

An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaS…

Fix: after 2.0.1
Fix from $1,600 2017-03-17
Mantisbt MEDIUM 6.1
CVE-2017-6799

A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript v…

Fix: after 2.2.0
Fix from $1,600 2017-03-10
Mantisbt MEDIUM 6.1
CVE-2017-6797

A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inj…

Fix: 1.3.7 / 2.2.1+
Fix from $1,600 2017-03-10
Mantisbt MEDIUM 6.1
CVE-2016-5364

Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitr…

Fix: after 1.2.19
Fix from $1,600 2017-02-17
Mantisbt MEDIUM 6.1
CVE-2016-6837

Cross-site scripting (XSS) vulnerability in MantisBT Filter API in MantisBT versions before 1.2.19, and versions 2.0.0-beta1, 1.3.0-beta1 allows remo…

Fix: after 1.2.18
Fix from $1,600 2017-01-10
Mantisbt MEDIUM 5.3
CVE-2014-9759

Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obta…

Patch available
Fix from $1,600 2016-04-11
Mantisbt MEDIUM 5.8
CVE-2015-1042

The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote …

No fix yet
Fix from $1,600 2015-02-10
Mantisbt MEDIUM 6.0
CVE-2014-9573

SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote administrators with FILE pr…

Fix: after 1.2.18
Fix from $1,600 2015-01-26
Mantisbt HIGH 7.5
CVE-2014-9572

MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain dat…

Fix: after 1.2.18
Fix from $1,950 2015-01-26
Mantisbt MEDIUM 5.0
CVE-2014-9388

bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.

Fix: after 1.2.17
Fix from $1,600 2014-12-17
Mantisbt MEDIUM 5.0
CVE-2014-8553

The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive informa…

Fix: after 1.2.17
Fix from $1,600 2014-12-17
Mantisbt MEDIUM 5.8
CVE-2014-6316

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to con…

Fix: after 1.2.17
Fix from $1,600 2014-12-12
Mantisbt HIGH 7.5
CVE-2014-9280

The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code…

Fix: after 1.2.17
Fix from $1,950 2014-12-08
Mantisbt MEDIUM 5.0
CVE-2014-9279

The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain data…

Patch available
Fix from $1,600 2014-12-08