mantisbt records
127 published records for vendor mantisbt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 4 · 3.1%
- Pre-auth RCE
- 19
- With a fix record
- 61.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')60
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-20 Improper Input Validation5
- CWE-287 Improper Authentication3
The weakness classes this vendor ships most often: where to look.
CWEAll records
127 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2017-7615Weaponized | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.mantisbt · mantisbt · CWE-640 | High8.8 | — | 91.1% | Apr 16, 2017 |
45Plan | CVE-2014-7146Weaponized | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptiomantisbt · mantisbt · CWE-20 | High7.5 | — | 50.6% | Nov 18, 2014 |
39Monitor | CVE-2019-15074No exploit | The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executiomantisbt · mantisbt · CWE-79 | Critical9.6 | — | 2.1% | Aug 21, 2019 |
38Monitor | CVE-2026-30849Proof of concept | MantisBT SOAP API has an authentication bypass vulnerability on MySQLmantisbt · mantisbt · CWE-305 | Critical9.3 | — | 2.4% | Mar 23, 2026 |
37Monitor | CVE-2014-8598Weaponized | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files viamantisbt · mantisbt · CWE-19 | Medium6.4 | — | 38.5% | Nov 18, 2014 |
37Monitor | CVE-2019-15715Proof of concept | MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.mantisbt · mantisbt · CWE-78 | High7.2 | — | 30.0% | Oct 9, 2019 |
36Monitor | CVE-2017-7309No exploit | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to injemantisbt · mantisbt · CWE-79 | Medium4.8 | — | 57.3% | Mar 31, 2017 |
35Monitor | CVE-2025-47776No exploit | MantisBT: Authentication bypass for some passwords due to PHP type jugglingmantisbt · mantisbt · CWE-305 | High8.8 | — | 0.3% | Nov 4, 2025 |
34Monitor | CVE-2026-33517No exploit | MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmationmantisbt · mantisbt · CWE-79 | High8.6 | — | 0.4% | Mar 23, 2026 |
34Monitor | CVE-2026-33548No exploit | MantisBT has Stored HTML Injection / XSS when displaying Tags in Timelinemantisbt · mantisbt · CWE-79 | High8.6 | — | 0.3% | Mar 23, 2026 |
33Monitor | CVE-2024-23830No exploit | MantisBT Host Header Injection vulnerabilitymantisbt · mantisbt · CWE-74 | High8.3 | — | 1.0% | Feb 20, 2024 |
32Monitor | CVE-2009-20001No exploit | An issue was discovered in MantisBT before 2.24.5.mantisbt · mantisbt · CWE-613 | High8.1 | — | 0.9% | Mar 7, 2021 |
31Monitor | CVE-2012-2691No exploit | The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackermantisbt · mantisbt · CWE-264 | High7.5 | — | 3.8% | Jun 16, 2012 |
31Monitor | CVE-2012-1123No exploit | The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatiomantisbt · mantisbt · CWE-287 | High7.5 | — | 3.7% | Jun 29, 2012 |
31Monitor | CVE-2014-9280No exploit | The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrarymantisbt · mantisbt · CWE-94 | High7.5 | — | 3.1% | Dec 8, 2014 |
31Monitor | CVE-2014-1608No exploit | SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to exmantisbt · mantisbt · CWE-89 | High7.5 | — | 3.0% | Mar 18, 2014 |
31Monitor | CVE-2014-9624No exploit | CAPTCHA bypass vulnerability in MantisBT before 1.2.19.mantisbt · mantisbt · CWE-287 | High7.5 | — | 3.0% | Sep 12, 2017 |
31Monitor | CVE-2014-1609No exploit | Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pamantisbt · mantisbt · CWE-89 | High7.5 | — | 3.0% | Mar 20, 2014 |
31Monitor | CVE-2014-9572No exploit | MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to omantisbt · mantisbt · CWE-284 | High7.5 | — | 2.5% | Jan 26, 2015 |
31Monitor | CVE-2014-8554No exploit | SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remotmantisbt · mantisbt · CWE-89 | High7.5 | — | 2.4% | Nov 13, 2014 |
31Monitor | CVE-2014-9089No exploit | Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL comantisbt · mantisbt · CWE-89 | High7.5 | — | 2.4% | Nov 28, 2014 |
31Monitor | CVE-2021-43257No exploit | Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain mantisbt · mantisbt · CWE-1236 | High7.8 | — | 1.0% | Apr 14, 2022 |
30Monitor | CVE-2011-3357No exploit | Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute armantisbt · mantisbt · CWE-22 | Medium6.8 | — | 9.3% | Sep 21, 2011 |
30Monitor | CVE-2020-35849No exploit | An issue was discovered in MantisBT before 2.24.4.mantisbt · mantisbt · CWE-639 | High7.5 | — | 1.6% | Dec 30, 2020 |
30Monitor | CVE-2025-46556No exploit | MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Lengthmantisbt · mantisbt · CWE-770 | High7.5 | — | 0.4% | Nov 3, 2025 |
- CVE-2017-761562This week
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
HighCVSS 8.8WeaponizedEPSS 91%mantisbt · mantisbtApr 16, 2017
- CVE-2014-714645Plan
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptio
HighCVSS 7.5WeaponizedEPSS 51%mantisbt · mantisbtNov 18, 2014
- CVE-2019-1507439Monitor
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executio
CriticalCVSS 9.6No exploitEPSS 2%mantisbt · mantisbtAug 21, 2019
- CVE-2026-3084938Monitor
MantisBT SOAP API has an authentication bypass vulnerability on MySQL
CriticalCVSS 9.3Proof of conceptEPSS 2%mantisbt · mantisbtMar 23, 2026
- CVE-2014-859837Monitor
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via
MediumCVSS 6.4WeaponizedEPSS 38%mantisbt · mantisbtNov 18, 2014
- CVE-2019-1571537Monitor
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
HighCVSS 7.2Proof of conceptEPSS 30%mantisbt · mantisbtOct 9, 2019
- CVE-2017-730936Monitor
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inje
MediumCVSS 4.8No exploitEPSS 57%mantisbt · mantisbtMar 31, 2017
- CVE-2025-4777635Monitor
MantisBT: Authentication bypass for some passwords due to PHP type juggling
HighCVSS 8.8No exploitEPSS 0%mantisbt · mantisbtNov 4, 2025
- CVE-2026-3351734Monitor
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
HighCVSS 8.6No exploitEPSS 0%mantisbt · mantisbtMar 23, 2026
- CVE-2026-3354834Monitor
MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline
HighCVSS 8.6No exploitEPSS 0%mantisbt · mantisbtMar 23, 2026
- CVE-2024-2383033Monitor
MantisBT Host Header Injection vulnerability
HighCVSS 8.3No exploitEPSS 1%mantisbt · mantisbtFeb 20, 2024
- CVE-2009-2000132Monitor
An issue was discovered in MantisBT before 2.24.5.
HighCVSS 8.1No exploitEPSS 1%mantisbt · mantisbtMar 7, 2021
- CVE-2012-269131Monitor
The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attacker
HighCVSS 7.5No exploitEPSS 4%mantisbt · mantisbtJun 16, 2012
- CVE-2012-112331Monitor
The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatio
HighCVSS 7.5No exploitEPSS 4%mantisbt · mantisbtJun 29, 2012
- CVE-2014-928031Monitor
The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary
HighCVSS 7.5No exploitEPSS 3%mantisbt · mantisbtDec 8, 2014
- CVE-2014-160831Monitor
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to ex
HighCVSS 7.5No exploitEPSS 3%mantisbt · mantisbtMar 18, 2014
- CVE-2014-962431Monitor
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
HighCVSS 7.5No exploitEPSS 3%mantisbt · mantisbtSep 12, 2017
- CVE-2014-160931Monitor
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pa
HighCVSS 7.5No exploitEPSS 3%mantisbt · mantisbtMar 20, 2014
- CVE-2014-957231Monitor
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to o
HighCVSS 7.5No exploitEPSS 2%mantisbt · mantisbtJan 26, 2015
- CVE-2014-855431Monitor
SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remot
HighCVSS 7.5No exploitEPSS 2%mantisbt · mantisbtNov 13, 2014
- CVE-2014-908931Monitor
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL co
HighCVSS 7.5No exploitEPSS 2%mantisbt · mantisbtNov 28, 2014
- CVE-2021-4325731Monitor
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain
HighCVSS 7.8No exploitEPSS 1%mantisbt · mantisbtApr 14, 2022
- CVE-2011-335730Monitor
Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute ar
MediumCVSS 6.8No exploitEPSS 9%mantisbt · mantisbtSep 21, 2011
- CVE-2020-3584930Monitor
An issue was discovered in MantisBT before 2.24.4.
HighCVSS 7.5No exploitEPSS 2%mantisbt · mantisbtDec 30, 2020
- CVE-2025-4655630Monitor
MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length
HighCVSS 7.5No exploitEPSS 0%mantisbt · mantisbtNov 3, 2025