Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2018-17782 A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attacke… Mantisbt after 2.17.1 Fix from $1,6002018-10-30 MEDIUM 5.4 CVE-2018-17783 A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attac… Mantisbt after 2.17.1 Fix from $1,6002018-10-30 MEDIUM 6.1 CVE-2018-16362 An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site scripting (XSS) vulnerability i… Source Integration 1.5.9 / 2.1.5+ Fix from $1,6002018-09-02 MEDIUM 6.1 CVE-2018-13055 A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers … Mantisbt after 2.15.0 Fix from $1,6002018-08-03 MEDIUM 6.1 CVE-2018-14504 An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter … Mantisbt after 2.15.0 Fix from $1,6002018-08-03 MEDIUM 5.3 CVE-2018-6526 view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parame… Mantisbt after 2.10.0 Fix from $1,6002018-02-02 HIGH 7.5 CVE-2014-9624 CAPTCHA bypass vulnerability in MantisBT before 1.2.19. Mantisbt after 1.2.18 Fix from $1,9502017-09-12 MEDIUM 6.1 CVE-2015-2046 Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20. Mantisbt Patch available Fix from $1,6002017-08-28 MEDIUM 6.5 CVE-2014-9701 Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web scri… Mantisbt after 1.2.18 Fix from $1,6002017-08-09 MEDIUM 6.1 CVE-2017-12061 An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under user control in the MantisBT in… Mantisbt 1.3.12 / 2.5.2+ Fix from $1,6002017-08-01 MEDIUM 6.1 CVE-2017-12062 An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Ma… Mantisbt Patch available Fix from $1,6002017-08-01 MEDIUM 5.3 CVE-2015-5059 The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc_threshold) is set to ANYBODY… Mantisbt after 1.2.19 Fix from $1,6002017-08-01 MEDIUM 6.5 CVE-2017-7620 MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpret… Mantisbt after 1.3.10 Fix from $1,6002017-05-21 MEDIUM 6.1 CVE-2017-7897 A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x before 2.3.2) Timeline include page, used in My View (my_view_page.php) and User In… Mantisbt Patch available Fix from $1,6002017-04-18 HIGH 8.8 CVE-2017-7615EPSS 91% MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. Mantisbt after 2.3.0 Fix from $1,9502017-04-16 MEDIUM 6.1 CVE-2017-7222 A cross-site scripting (XSS) vulnerability in MantisBT before 2.1.1 allows remote attackers to inject arbitrary HTML or JavaScript (if MantisBT's CSP… Mantisbt after 2.1.0 Fix from $1,6002017-03-22 MEDIUM 6.1 CVE-2017-6958 An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaS… Source Integration after 2.0.1 Fix from $1,6002017-03-17 MEDIUM 6.1 CVE-2017-6799 A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript v… Mantisbt after 2.2.0 Fix from $1,6002017-03-10 MEDIUM 6.1 CVE-2017-6797 A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inj… Mantisbt 1.3.7 / 2.2.1+ Fix from $1,6002017-03-10 MEDIUM 6.1 CVE-2016-5364 Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitr… Mantisbt after 1.2.19 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2016-6837 Cross-site scripting (XSS) vulnerability in MantisBT Filter API in MantisBT versions before 1.2.19, and versions 2.0.0-beta1, 1.3.0-beta1 allows remo… Mantisbt after 1.2.18 Fix from $1,6002017-01-10 MEDIUM 5.3 CVE-2014-9759 Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obta… Mantisbt Patch available Fix from $1,6002016-04-11 MEDIUM 5.8 CVE-2015-1042 The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote … Mantisbt No fix yet Fix from $1,6002015-02-10 MEDIUM 6.0 CVE-2014-9573 SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote administrators with FILE pr… Mantisbt after 1.2.18 Fix from $1,6002015-01-26 HIGH 7.5 CVE-2014-9572 MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain dat… Mantisbt after 1.2.18 Fix from $1,9502015-01-26 MEDIUM 5.0 CVE-2014-9388 bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter. Mantisbt after 1.2.17 Fix from $1,6002014-12-17 MEDIUM 5.0 CVE-2014-8553 The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive informa… Mantisbt after 1.2.17 Fix from $1,6002014-12-17 MEDIUM 5.8 CVE-2014-6316 core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to con… Mantisbt after 1.2.17 Fix from $1,6002014-12-12 HIGH 7.5 CVE-2014-9280 The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code… Mantisbt after 1.2.17 Fix from $1,9502014-12-08 MEDIUM 5.0 CVE-2014-9279 The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain data… Mantisbt Patch available Fix from $1,6002014-12-08