Записи mantisbt
127 опубликованных записей вендора mantisbt.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 4 · 3,1 %
- Pre-auth RCE
- 19
- С записью об исправлении
- 61,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')60
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-20 Improper Input Validation5
- CWE-287 Improper Authentication3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
127 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2017-7615Готовый эксплойт | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.mantisbt · mantisbt · CWE-640 | Высокая8,8 | — | 91,1 % | 16 апр. 2017 г. |
45В плане | CVE-2014-7146Готовый эксплойт | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptiomantisbt · mantisbt · CWE-20 | Высокая7,5 | — | 50,6 % | 18 нояб. 2014 г. |
39Наблюдать | CVE-2019-15074Эксплойта нет | The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executiomantisbt · mantisbt · CWE-79 | Критическая9,6 | — | 2,1 % | 21 авг. 2019 г. |
38Наблюдать | CVE-2026-30849Proof of concept | MantisBT SOAP API has an authentication bypass vulnerability on MySQLmantisbt · mantisbt · CWE-305 | Критическая9,3 | — | 2,4 % | 23 мар. 2026 г. |
37Наблюдать | CVE-2014-8598Готовый эксплойт | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files viamantisbt · mantisbt · CWE-19 | Средняя6,4 | — | 38,5 % | 18 нояб. 2014 г. |
37Наблюдать | CVE-2019-15715Proof of concept | MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.mantisbt · mantisbt · CWE-78 | Высокая7,2 | — | 30,0 % | 9 окт. 2019 г. |
36Наблюдать | CVE-2017-7309Эксплойта нет | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to injemantisbt · mantisbt · CWE-79 | Средняя4,8 | — | 57,3 % | 31 мар. 2017 г. |
35Наблюдать | CVE-2025-47776Эксплойта нет | MantisBT: Authentication bypass for some passwords due to PHP type jugglingmantisbt · mantisbt · CWE-305 | Высокая8,8 | — | 0,3 % | 4 нояб. 2025 г. |
34Наблюдать | CVE-2026-33517Эксплойта нет | MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmationmantisbt · mantisbt · CWE-79 | Высокая8,6 | — | 0,4 % | 23 мар. 2026 г. |
34Наблюдать | CVE-2026-33548Эксплойта нет | MantisBT has Stored HTML Injection / XSS when displaying Tags in Timelinemantisbt · mantisbt · CWE-79 | Высокая8,6 | — | 0,3 % | 23 мар. 2026 г. |
33Наблюдать | CVE-2024-23830Эксплойта нет | MantisBT Host Header Injection vulnerabilitymantisbt · mantisbt · CWE-74 | Высокая8,3 | — | 1,0 % | 20 февр. 2024 г. |
32Наблюдать | CVE-2009-20001Эксплойта нет | An issue was discovered in MantisBT before 2.24.5.mantisbt · mantisbt · CWE-613 | Высокая8,1 | — | 0,9 % | 7 мар. 2021 г. |
31Наблюдать | CVE-2012-2691Эксплойта нет | The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackermantisbt · mantisbt · CWE-264 | Высокая7,5 | — | 3,8 % | 16 июн. 2012 г. |
31Наблюдать | CVE-2012-1123Эксплойта нет | The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatiomantisbt · mantisbt · CWE-287 | Высокая7,5 | — | 3,7 % | 29 июн. 2012 г. |
31Наблюдать | CVE-2014-9280Эксплойта нет | The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrarymantisbt · mantisbt · CWE-94 | Высокая7,5 | — | 3,1 % | 8 дек. 2014 г. |
31Наблюдать | CVE-2014-1608Эксплойта нет | SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to exmantisbt · mantisbt · CWE-89 | Высокая7,5 | — | 3,0 % | 18 мар. 2014 г. |
31Наблюдать | CVE-2014-9624Эксплойта нет | CAPTCHA bypass vulnerability in MantisBT before 1.2.19.mantisbt · mantisbt · CWE-287 | Высокая7,5 | — | 3,0 % | 12 сент. 2017 г. |
31Наблюдать | CVE-2014-1609Эксплойта нет | Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pamantisbt · mantisbt · CWE-89 | Высокая7,5 | — | 3,0 % | 20 мар. 2014 г. |
31Наблюдать | CVE-2014-9572Эксплойта нет | MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to omantisbt · mantisbt · CWE-284 | Высокая7,5 | — | 2,5 % | 26 янв. 2015 г. |
31Наблюдать | CVE-2014-8554Эксплойта нет | SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remotmantisbt · mantisbt · CWE-89 | Высокая7,5 | — | 2,4 % | 13 нояб. 2014 г. |
31Наблюдать | CVE-2014-9089Эксплойта нет | Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL comantisbt · mantisbt · CWE-89 | Высокая7,5 | — | 2,4 % | 28 нояб. 2014 г. |
31Наблюдать | CVE-2021-43257Эксплойта нет | Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain mantisbt · mantisbt · CWE-1236 | Высокая7,8 | — | 1,0 % | 14 апр. 2022 г. |
30Наблюдать | CVE-2011-3357Эксплойта нет | Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute armantisbt · mantisbt · CWE-22 | Средняя6,8 | — | 9,3 % | 21 сент. 2011 г. |
30Наблюдать | CVE-2020-35849Эксплойта нет | An issue was discovered in MantisBT before 2.24.4.mantisbt · mantisbt · CWE-639 | Высокая7,5 | — | 1,6 % | 30 дек. 2020 г. |
30Наблюдать | CVE-2025-46556Эксплойта нет | MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Lengthmantisbt · mantisbt · CWE-770 | Высокая7,5 | — | 0,4 % | 3 нояб. 2025 г. |
- CVE-2017-761562На этой неделе
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 91 %mantisbt · mantisbt16 апр. 2017 г.
- CVE-2014-714645В плане
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptio
ВысокаяCVSS 7,5Готовый эксплойтEPSS 51 %mantisbt · mantisbt18 нояб. 2014 г.
- CVE-2019-1507439Наблюдать
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executio
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %mantisbt · mantisbt21 авг. 2019 г.
- CVE-2026-3084938Наблюдать
MantisBT SOAP API has an authentication bypass vulnerability on MySQL
КритическаяCVSS 9,3Proof of conceptEPSS 2 %mantisbt · mantisbt23 мар. 2026 г.
- CVE-2014-859837Наблюдать
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via
СредняяCVSS 6,4Готовый эксплойтEPSS 38 %mantisbt · mantisbt18 нояб. 2014 г.
- CVE-2019-1571537Наблюдать
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
ВысокаяCVSS 7,2Proof of conceptEPSS 30 %mantisbt · mantisbt9 окт. 2019 г.
- CVE-2017-730936Наблюдать
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inje
СредняяCVSS 4,8Эксплойта нетEPSS 57 %mantisbt · mantisbt31 мар. 2017 г.
- CVE-2025-4777635Наблюдать
MantisBT: Authentication bypass for some passwords due to PHP type juggling
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mantisbt · mantisbt4 нояб. 2025 г.
- CVE-2026-3351734Наблюдать
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %mantisbt · mantisbt23 мар. 2026 г.
- CVE-2026-3354834Наблюдать
MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %mantisbt · mantisbt23 мар. 2026 г.
- CVE-2024-2383033Наблюдать
MantisBT Host Header Injection vulnerability
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %mantisbt · mantisbt20 февр. 2024 г.
- CVE-2009-2000132Наблюдать
An issue was discovered in MantisBT before 2.24.5.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %mantisbt · mantisbt7 мар. 2021 г.
- CVE-2012-269131Наблюдать
The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mantisbt · mantisbt16 июн. 2012 г.
- CVE-2012-112331Наблюдать
The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatio
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mantisbt · mantisbt29 июн. 2012 г.
- CVE-2014-928031Наблюдать
The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mantisbt · mantisbt8 дек. 2014 г.
- CVE-2014-160831Наблюдать
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to ex
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mantisbt · mantisbt18 мар. 2014 г.
- CVE-2014-962431Наблюдать
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mantisbt · mantisbt12 сент. 2017 г.
- CVE-2014-160931Наблюдать
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pa
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mantisbt · mantisbt20 мар. 2014 г.
- CVE-2014-957231Наблюдать
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to o
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantisbt · mantisbt26 янв. 2015 г.
- CVE-2014-855431Наблюдать
SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remot
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantisbt · mantisbt13 нояб. 2014 г.
- CVE-2014-908931Наблюдать
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL co
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantisbt · mantisbt28 нояб. 2014 г.
- CVE-2021-4325731Наблюдать
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %mantisbt · mantisbt14 апр. 2022 г.
- CVE-2011-335730Наблюдать
Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute ar
СредняяCVSS 6,8Эксплойта нетEPSS 9 %mantisbt · mantisbt21 сент. 2011 г.
- CVE-2020-3584930Наблюдать
An issue was discovered in MantisBT before 2.24.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantisbt · mantisbt30 дек. 2020 г.
- CVE-2025-4655630Наблюдать
MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %mantisbt · mantisbt3 нояб. 2025 г.