Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-33517 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), improper escaping of its name… Mantisbt Patch available Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-33548 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (… Mantisbt Patch available Fix from $1,6002026-03-23 CRITICAL 9.8 CVE-2026-30849 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authenti… Mantisbt 2.28.1+ Fix from $2,3002026-03-23 MEDIUM 5.4 CVE-2025-55155 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail a… Mantisbt 2.27.2+ Fix from $1,6002025-11-04 CRITICAL 9.1 CVE-2025-47776 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===) comparison in the authentic… Mantisbt 2.27.2+ Fix from $2,3002025-11-04 HIGH 7.5 CVE-2025-46556 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs b… Mantisbt 2.27.2+ Fix from $1,9502025-11-04 MEDIUM 6.5 CVE-2024-45792 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve inf… Mantisbt 2.26.4+ Fix from $1,6002024-09-30 MEDIUM 5.3 CVE-2024-34080 MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have… Mantisbt 2.26.2+ Fix from $1,6002024-05-14 HIGH 7.3 CVE-2024-34077 MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an a… Mantisbt 2.26.2+ Fix from $1,9502024-05-14 HIGH 8.3 CVE-2024-23830 MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hija… Mantisbt 2.26.1+ Fix from $1,9502024-02-20 MEDIUM 6.1 CVE-2023-49802 The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1,… Linked Custom Fields 2.0.1+ Fix from $1,6002023-12-11 MEDIUM 5.4 CVE-2022-33910 An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or a… Mantisbt 2.25.5+ Fix from $1,6002022-06-24 MEDIUM 6.1 CVE-2022-28508EPSS 5% An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to in… Mantisbt 2.25.2+ Fix from $1,6002022-05-04 HIGH 7.8 CVE-2021-43257 Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to… Mantisbt 2.25.3+ Fix from $1,9502022-04-14 MEDIUM 6.1 CVE-2022-26144 An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in ma… Mantisbt 2.25.3+ Fix from $1,6002022-04-13 MEDIUM 6.1 CVE-2021-33557 An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attack… Mantisbt 2.25.2+ Fix from $1,6002021-06-17 HIGH 8.1 CVE-2009-20001 An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., t… Mantisbt 2.24.5+ Fix from $1,9502021-03-07 MEDIUM 6.1 CVE-2020-35571 An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is n… Mantisbt after 2.24.3 Fix from $1,6002021-02-22 MEDIUM 6.5 CVE-2020-29604 An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues… Mantisbt 2.24.4+ Fix from $1,6002021-01-29 MEDIUM 5.3 CVE-2020-36192 An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the Summary field of private Issue… Source Integration 2.4.1+ Fix from $1,6002021-01-18 MEDIUM 6.5 CVE-2020-28413 In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP. Mantisbt No fix yet Fix from $1,6002020-12-30 HIGH 7.5 CVE-2020-35849 An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view th… Mantisbt 2.24.4+ Fix from $1,9502020-12-30 MEDIUM 5.4 CVE-2020-16266 An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML i… Mantisbt 2.24.2+ Fix from $1,6002020-08-12 MEDIUM 6.1 CVE-2019-15539 The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing ex… Mantisbt 2.21.3+ Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2020-8981 A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_d… Source Integration 1.6.2 / 2.3.1+ Fix from $1,6002020-02-13 MEDIUM 6.1 CVE-2009-2802 MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting… Mantisbt 1.2.2+ Fix from $1,6002019-11-09 MEDIUM 5.4 CVE-2013-1932 A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated us… Mantisbt Mitigation only Fix from $1,6002019-10-31 HIGH 7.2 CVE-2019-15715EPSS 30% MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution. Mantisbt 1.3.20 / 2.22.1+ Fix from $1,9502019-10-09 CRITICAL 9.6 CVE-2019-15074 The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbi… Mantisbt after 2.21.1 Fix from $2,3002019-08-21 MEDIUM 6.5 CVE-2018-9839 An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any u… Mantisbt after 1.3.14 Fix from $1,6002019-06-06