Перейти к содержимому
Noroxi

Записи mantisbt

127 опубликованных записей вендора mantisbt.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
4 · 3,1 %
Pre-auth RCE
19
С записью об исправлении
61,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

127 записей
  • CVE-2017-7615
    62На этой неделе

    MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 91 %

    mantisbt · mantisbt16 апр. 2017 г.

  • CVE-2014-7146
    45В плане

    The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptio

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 51 %

    mantisbt · mantisbt18 нояб. 2014 г.

  • CVE-2019-15074
    39Наблюдать

    The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executio

    КритическаяCVSS 9,6Эксплойта нетEPSS 2 %

    mantisbt · mantisbt21 авг. 2019 г.

  • CVE-2026-30849
    38Наблюдать

    MantisBT SOAP API has an authentication bypass vulnerability on MySQL

    КритическаяCVSS 9,3Proof of conceptEPSS 2 %

    mantisbt · mantisbt23 мар. 2026 г.

  • CVE-2014-8598
    37Наблюдать

    The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via

    СредняяCVSS 6,4Готовый эксплойтEPSS 38 %

    mantisbt · mantisbt18 нояб. 2014 г.

  • CVE-2019-15715
    37Наблюдать

    MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.

    ВысокаяCVSS 7,2Proof of conceptEPSS 30 %

    mantisbt · mantisbt9 окт. 2019 г.

  • CVE-2017-7309
    36Наблюдать

    A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inje

    СредняяCVSS 4,8Эксплойта нетEPSS 57 %

    mantisbt · mantisbt31 мар. 2017 г.

  • CVE-2025-47776
    35Наблюдать

    MantisBT: Authentication bypass for some passwords due to PHP type juggling

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    mantisbt · mantisbt4 нояб. 2025 г.

  • CVE-2026-33517
    34Наблюдать

    MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    mantisbt · mantisbt23 мар. 2026 г.

  • CVE-2026-33548
    34Наблюдать

    MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    mantisbt · mantisbt23 мар. 2026 г.

  • CVE-2024-23830
    33Наблюдать

    MantisBT Host Header Injection vulnerability

    ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %

    mantisbt · mantisbt20 февр. 2024 г.

  • CVE-2009-20001
    32Наблюдать

    An issue was discovered in MantisBT before 2.24.5.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    mantisbt · mantisbt7 мар. 2021 г.

  • CVE-2012-2691
    31Наблюдать

    The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attacker

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    mantisbt · mantisbt16 июн. 2012 г.

  • CVE-2012-1123
    31Наблюдать

    The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatio

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    mantisbt · mantisbt29 июн. 2012 г.

  • CVE-2014-9280
    31Наблюдать

    The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    mantisbt · mantisbt8 дек. 2014 г.

  • CVE-2014-1608
    31Наблюдать

    SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to ex

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    mantisbt · mantisbt18 мар. 2014 г.

  • CVE-2014-9624
    31Наблюдать

    CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    mantisbt · mantisbt12 сент. 2017 г.

  • CVE-2014-1609
    31Наблюдать

    Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pa

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    mantisbt · mantisbt20 мар. 2014 г.

  • CVE-2014-9572
    31Наблюдать

    MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to o

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantisbt · mantisbt26 янв. 2015 г.

  • CVE-2014-8554
    31Наблюдать

    SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remot

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantisbt · mantisbt13 нояб. 2014 г.

  • CVE-2014-9089
    31Наблюдать

    Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL co

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantisbt · mantisbt28 нояб. 2014 г.

  • CVE-2021-43257
    31Наблюдать

    Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    mantisbt · mantisbt14 апр. 2022 г.

  • CVE-2011-3357
    30Наблюдать

    Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute ar

    СредняяCVSS 6,8Эксплойта нетEPSS 9 %

    mantisbt · mantisbt21 сент. 2011 г.

  • CVE-2020-35849
    30Наблюдать

    An issue was discovered in MantisBT before 2.24.4.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantisbt · mantisbt30 дек. 2020 г.

  • CVE-2025-46556
    30Наблюдать

    MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    mantisbt · mantisbt3 нояб. 2025 г.