Skip to content
Noroxi

mantisbt records

127 published records for vendor mantisbt.

All records

127 records
  • CVE-2017-7615
    62This week

    MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

    HighCVSS 8.8WeaponizedEPSS 91%

    mantisbt · mantisbtApr 16, 2017

  • The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptio

    HighCVSS 7.5WeaponizedEPSS 51%

    mantisbt · mantisbtNov 18, 2014

  • The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executio

    CriticalCVSS 9.6No exploitEPSS 2%

    mantisbt · mantisbtAug 21, 2019

  • MantisBT SOAP API has an authentication bypass vulnerability on MySQL

    CriticalCVSS 9.3Proof of conceptEPSS 2%

    mantisbt · mantisbtMar 23, 2026

  • CVE-2014-8598
    37Monitor

    The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via

    MediumCVSS 6.4WeaponizedEPSS 38%

    mantisbt · mantisbtNov 18, 2014

  • MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.

    HighCVSS 7.2Proof of conceptEPSS 30%

    mantisbt · mantisbtOct 9, 2019

  • CVE-2017-7309
    36Monitor

    A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inje

    MediumCVSS 4.8No exploitEPSS 57%

    mantisbt · mantisbtMar 31, 2017

  • MantisBT: Authentication bypass for some passwords due to PHP type juggling

    HighCVSS 8.8No exploitEPSS 0%

    mantisbt · mantisbtNov 4, 2025

  • MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation

    HighCVSS 8.6No exploitEPSS 0%

    mantisbt · mantisbtMar 23, 2026

  • MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline

    HighCVSS 8.6No exploitEPSS 0%

    mantisbt · mantisbtMar 23, 2026

  • MantisBT Host Header Injection vulnerability

    HighCVSS 8.3No exploitEPSS 1%

    mantisbt · mantisbtFeb 20, 2024

  • An issue was discovered in MantisBT before 2.24.5.

    HighCVSS 8.1No exploitEPSS 1%

    mantisbt · mantisbtMar 7, 2021

  • CVE-2012-2691
    31Monitor

    The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attacker

    HighCVSS 7.5No exploitEPSS 4%

    mantisbt · mantisbtJun 16, 2012

  • CVE-2012-1123
    31Monitor

    The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatio

    HighCVSS 7.5No exploitEPSS 4%

    mantisbt · mantisbtJun 29, 2012

  • CVE-2014-9280
    31Monitor

    The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary

    HighCVSS 7.5No exploitEPSS 3%

    mantisbt · mantisbtDec 8, 2014

  • CVE-2014-1608
    31Monitor

    SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to ex

    HighCVSS 7.5No exploitEPSS 3%

    mantisbt · mantisbtMar 18, 2014

  • CVE-2014-9624
    31Monitor

    CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

    HighCVSS 7.5No exploitEPSS 3%

    mantisbt · mantisbtSep 12, 2017

  • CVE-2014-1609
    31Monitor

    Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pa

    HighCVSS 7.5No exploitEPSS 3%

    mantisbt · mantisbtMar 20, 2014

  • CVE-2014-9572
    31Monitor

    MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to o

    HighCVSS 7.5No exploitEPSS 2%

    mantisbt · mantisbtJan 26, 2015

  • CVE-2014-8554
    31Monitor

    SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remot

    HighCVSS 7.5No exploitEPSS 2%

    mantisbt · mantisbtNov 13, 2014

  • CVE-2014-9089
    31Monitor

    Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL co

    HighCVSS 7.5No exploitEPSS 2%

    mantisbt · mantisbtNov 28, 2014

  • Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain

    HighCVSS 7.8No exploitEPSS 1%

    mantisbt · mantisbtApr 14, 2022

  • CVE-2011-3357
    30Monitor

    Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute ar

    MediumCVSS 6.8No exploitEPSS 9%

    mantisbt · mantisbtSep 21, 2011

  • An issue was discovered in MantisBT before 2.24.4.

    HighCVSS 7.5No exploitEPSS 2%

    mantisbt · mantisbtDec 30, 2020

  • MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length

    HighCVSS 7.5No exploitEPSS 0%

    mantisbt · mantisbtNov 3, 2025