İçeriğe atla
Noroxi

mantisbt kayıtları

mantisbt üreticisine ait 127 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
4 · %3,1
Pre-auth RCE
19
Düzeltme kaydı olan
%61,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

127 kayıt
  • CVE-2017-7615
    62Bu hafta

    MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %91

    mantisbt · mantisbt16 Nis 2017

  • CVE-2014-7146
    45Planlayın

    The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptio

    YüksekCVSS 7,5SilahlaştırılmışEPSS %51

    mantisbt · mantisbt18 Kas 2014

  • CVE-2019-15074
    39İzleyin

    The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executio

    KritikCVSS 9,6İstismar yokEPSS %2

    mantisbt · mantisbt21 Ağu 2019

  • CVE-2026-30849
    38İzleyin

    MantisBT SOAP API has an authentication bypass vulnerability on MySQL

    KritikCVSS 9,3Kavram kanıtıEPSS %2

    mantisbt · mantisbt23 Mar 2026

  • CVE-2014-8598
    37İzleyin

    The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via

    OrtaCVSS 6,4SilahlaştırılmışEPSS %38

    mantisbt · mantisbt18 Kas 2014

  • CVE-2019-15715
    37İzleyin

    MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.

    YüksekCVSS 7,2Kavram kanıtıEPSS %30

    mantisbt · mantisbt9 Eki 2019

  • CVE-2017-7309
    36İzleyin

    A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inje

    OrtaCVSS 4,8İstismar yokEPSS %57

    mantisbt · mantisbt31 Mar 2017

  • CVE-2025-47776
    35İzleyin

    MantisBT: Authentication bypass for some passwords due to PHP type juggling

    YüksekCVSS 8,8İstismar yokEPSS %0

    mantisbt · mantisbt4 Kas 2025

  • CVE-2026-33517
    34İzleyin

    MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation

    YüksekCVSS 8,6İstismar yokEPSS %0

    mantisbt · mantisbt23 Mar 2026

  • CVE-2026-33548
    34İzleyin

    MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline

    YüksekCVSS 8,6İstismar yokEPSS %0

    mantisbt · mantisbt23 Mar 2026

  • CVE-2024-23830
    33İzleyin

    MantisBT Host Header Injection vulnerability

    YüksekCVSS 8,3İstismar yokEPSS %1

    mantisbt · mantisbt20 Şub 2024

  • CVE-2009-20001
    32İzleyin

    An issue was discovered in MantisBT before 2.24.5.

    YüksekCVSS 8,1İstismar yokEPSS %1

    mantisbt · mantisbt7 Mar 2021

  • CVE-2012-2691
    31İzleyin

    The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attacker

    YüksekCVSS 7,5İstismar yokEPSS %4

    mantisbt · mantisbt16 Haz 2012

  • CVE-2012-1123
    31İzleyin

    The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatio

    YüksekCVSS 7,5İstismar yokEPSS %4

    mantisbt · mantisbt29 Haz 2012

  • CVE-2014-9280
    31İzleyin

    The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary

    YüksekCVSS 7,5İstismar yokEPSS %3

    mantisbt · mantisbt8 Ara 2014

  • CVE-2014-1608
    31İzleyin

    SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to ex

    YüksekCVSS 7,5İstismar yokEPSS %3

    mantisbt · mantisbt18 Mar 2014

  • CVE-2014-9624
    31İzleyin

    CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

    YüksekCVSS 7,5İstismar yokEPSS %3

    mantisbt · mantisbt12 Eyl 2017

  • CVE-2014-1609
    31İzleyin

    Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pa

    YüksekCVSS 7,5İstismar yokEPSS %3

    mantisbt · mantisbt20 Mar 2014

  • CVE-2014-9572
    31İzleyin

    MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to o

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantisbt · mantisbt26 Oca 2015

  • CVE-2014-8554
    31İzleyin

    SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remot

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantisbt · mantisbt13 Kas 2014

  • CVE-2014-9089
    31İzleyin

    Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL co

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantisbt · mantisbt28 Kas 2014

  • CVE-2021-43257
    31İzleyin

    Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain

    YüksekCVSS 7,8İstismar yokEPSS %1

    mantisbt · mantisbt14 Nis 2022

  • CVE-2011-3357
    30İzleyin

    Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute ar

    OrtaCVSS 6,8İstismar yokEPSS %9

    mantisbt · mantisbt21 Eyl 2011

  • CVE-2020-35849
    30İzleyin

    An issue was discovered in MantisBT before 2.24.4.

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantisbt · mantisbt30 Ara 2020

  • CVE-2025-46556
    30İzleyin

    MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length

    YüksekCVSS 7,5İstismar yokEPSS %0

    mantisbt · mantisbt3 Kas 2025