mantisbt kayıtları
mantisbt üreticisine ait 127 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 4 · %3,1
- Pre-auth RCE
- 19
- Düzeltme kaydı olan
- %61,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')60
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-20 Improper Input Validation5
- CWE-287 Improper Authentication3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
127 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2017-7615Silahlaştırılmış | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.mantisbt · mantisbt · CWE-640 | Yüksek8,8 | — | %91,1 | 16 Nis 2017 |
45Planlayın | CVE-2014-7146Silahlaştırılmış | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptiomantisbt · mantisbt · CWE-20 | Yüksek7,5 | — | %50,6 | 18 Kas 2014 |
39İzleyin | CVE-2019-15074İstismar yok | The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executiomantisbt · mantisbt · CWE-79 | Kritik9,6 | — | %2,1 | 21 Ağu 2019 |
38İzleyin | CVE-2026-30849Kavram kanıtı | MantisBT SOAP API has an authentication bypass vulnerability on MySQLmantisbt · mantisbt · CWE-305 | Kritik9,3 | — | %2,4 | 23 Mar 2026 |
37İzleyin | CVE-2014-8598Silahlaştırılmış | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files viamantisbt · mantisbt · CWE-19 | Orta6,4 | — | %38,5 | 18 Kas 2014 |
37İzleyin | CVE-2019-15715Kavram kanıtı | MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.mantisbt · mantisbt · CWE-78 | Yüksek7,2 | — | %30,0 | 9 Eki 2019 |
36İzleyin | CVE-2017-7309İstismar yok | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to injemantisbt · mantisbt · CWE-79 | Orta4,8 | — | %57,3 | 31 Mar 2017 |
35İzleyin | CVE-2025-47776İstismar yok | MantisBT: Authentication bypass for some passwords due to PHP type jugglingmantisbt · mantisbt · CWE-305 | Yüksek8,8 | — | %0,3 | 4 Kas 2025 |
34İzleyin | CVE-2026-33517İstismar yok | MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmationmantisbt · mantisbt · CWE-79 | Yüksek8,6 | — | %0,4 | 23 Mar 2026 |
34İzleyin | CVE-2026-33548İstismar yok | MantisBT has Stored HTML Injection / XSS when displaying Tags in Timelinemantisbt · mantisbt · CWE-79 | Yüksek8,6 | — | %0,3 | 23 Mar 2026 |
33İzleyin | CVE-2024-23830İstismar yok | MantisBT Host Header Injection vulnerabilitymantisbt · mantisbt · CWE-74 | Yüksek8,3 | — | %1,0 | 20 Şub 2024 |
32İzleyin | CVE-2009-20001İstismar yok | An issue was discovered in MantisBT before 2.24.5.mantisbt · mantisbt · CWE-613 | Yüksek8,1 | — | %0,9 | 7 Mar 2021 |
31İzleyin | CVE-2012-2691İstismar yok | The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackermantisbt · mantisbt · CWE-264 | Yüksek7,5 | — | %3,8 | 16 Haz 2012 |
31İzleyin | CVE-2012-1123İstismar yok | The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatiomantisbt · mantisbt · CWE-287 | Yüksek7,5 | — | %3,7 | 29 Haz 2012 |
31İzleyin | CVE-2014-9280İstismar yok | The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrarymantisbt · mantisbt · CWE-94 | Yüksek7,5 | — | %3,1 | 8 Ara 2014 |
31İzleyin | CVE-2014-1608İstismar yok | SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to exmantisbt · mantisbt · CWE-89 | Yüksek7,5 | — | %3,0 | 18 Mar 2014 |
31İzleyin | CVE-2014-9624İstismar yok | CAPTCHA bypass vulnerability in MantisBT before 1.2.19.mantisbt · mantisbt · CWE-287 | Yüksek7,5 | — | %3,0 | 12 Eyl 2017 |
31İzleyin | CVE-2014-1609İstismar yok | Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pamantisbt · mantisbt · CWE-89 | Yüksek7,5 | — | %3,0 | 20 Mar 2014 |
31İzleyin | CVE-2014-9572İstismar yok | MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to omantisbt · mantisbt · CWE-284 | Yüksek7,5 | — | %2,5 | 26 Oca 2015 |
31İzleyin | CVE-2014-8554İstismar yok | SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remotmantisbt · mantisbt · CWE-89 | Yüksek7,5 | — | %2,4 | 13 Kas 2014 |
31İzleyin | CVE-2014-9089İstismar yok | Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL comantisbt · mantisbt · CWE-89 | Yüksek7,5 | — | %2,4 | 28 Kas 2014 |
31İzleyin | CVE-2021-43257İstismar yok | Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain mantisbt · mantisbt · CWE-1236 | Yüksek7,8 | — | %1,0 | 14 Nis 2022 |
30İzleyin | CVE-2011-3357İstismar yok | Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute armantisbt · mantisbt · CWE-22 | Orta6,8 | — | %9,3 | 21 Eyl 2011 |
30İzleyin | CVE-2020-35849İstismar yok | An issue was discovered in MantisBT before 2.24.4.mantisbt · mantisbt · CWE-639 | Yüksek7,5 | — | %1,6 | 30 Ara 2020 |
30İzleyin | CVE-2025-46556İstismar yok | MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Lengthmantisbt · mantisbt · CWE-770 | Yüksek7,5 | — | %0,4 | 3 Kas 2025 |
- CVE-2017-761562Bu hafta
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
YüksekCVSS 8,8SilahlaştırılmışEPSS %91mantisbt · mantisbt16 Nis 2017
- CVE-2014-714645Planlayın
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) descriptio
YüksekCVSS 7,5SilahlaştırılmışEPSS %51mantisbt · mantisbt18 Kas 2014
- CVE-2019-1507439İzleyin
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing executio
KritikCVSS 9,6İstismar yokEPSS %2mantisbt · mantisbt21 Ağu 2019
- CVE-2026-3084938İzleyin
MantisBT SOAP API has an authentication bypass vulnerability on MySQL
KritikCVSS 9,3Kavram kanıtıEPSS %2mantisbt · mantisbt23 Mar 2026
- CVE-2014-859837İzleyin
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via
OrtaCVSS 6,4SilahlaştırılmışEPSS %38mantisbt · mantisbt18 Kas 2014
- CVE-2019-1571537İzleyin
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
YüksekCVSS 7,2Kavram kanıtıEPSS %30mantisbt · mantisbt9 Eki 2019
- CVE-2017-730936İzleyin
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inje
OrtaCVSS 4,8İstismar yokEPSS %57mantisbt · mantisbt31 Mar 2017
- CVE-2025-4777635İzleyin
MantisBT: Authentication bypass for some passwords due to PHP type juggling
YüksekCVSS 8,8İstismar yokEPSS %0mantisbt · mantisbt4 Kas 2025
- CVE-2026-3351734İzleyin
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
YüksekCVSS 8,6İstismar yokEPSS %0mantisbt · mantisbt23 Mar 2026
- CVE-2026-3354834İzleyin
MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline
YüksekCVSS 8,6İstismar yokEPSS %0mantisbt · mantisbt23 Mar 2026
- CVE-2024-2383033İzleyin
MantisBT Host Header Injection vulnerability
YüksekCVSS 8,3İstismar yokEPSS %1mantisbt · mantisbt20 Şub 2024
- CVE-2009-2000132İzleyin
An issue was discovered in MantisBT before 2.24.5.
YüksekCVSS 8,1İstismar yokEPSS %1mantisbt · mantisbt7 Mar 2021
- CVE-2012-269131İzleyin
The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attacker
YüksekCVSS 7,5İstismar yokEPSS %4mantisbt · mantisbt16 Haz 2012
- CVE-2012-112331İzleyin
The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authenticatio
YüksekCVSS 7,5İstismar yokEPSS %4mantisbt · mantisbt29 Haz 2012
- CVE-2014-928031İzleyin
The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary
YüksekCVSS 7,5İstismar yokEPSS %3mantisbt · mantisbt8 Ara 2014
- CVE-2014-160831İzleyin
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to ex
YüksekCVSS 7,5İstismar yokEPSS %3mantisbt · mantisbt18 Mar 2014
- CVE-2014-962431İzleyin
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
YüksekCVSS 7,5İstismar yokEPSS %3mantisbt · mantisbt12 Eyl 2017
- CVE-2014-160931İzleyin
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified pa
YüksekCVSS 7,5İstismar yokEPSS %3mantisbt · mantisbt20 Mar 2014
- CVE-2014-957231İzleyin
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to o
YüksekCVSS 7,5İstismar yokEPSS %2mantisbt · mantisbt26 Oca 2015
- CVE-2014-855431İzleyin
SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remot
YüksekCVSS 7,5İstismar yokEPSS %2mantisbt · mantisbt13 Kas 2014
- CVE-2014-908931İzleyin
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL co
YüksekCVSS 7,5İstismar yokEPSS %2mantisbt · mantisbt28 Kas 2014
- CVE-2021-4325731İzleyin
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain
YüksekCVSS 7,8İstismar yokEPSS %1mantisbt · mantisbt14 Nis 2022
- CVE-2011-335730İzleyin
Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute ar
OrtaCVSS 6,8İstismar yokEPSS %9mantisbt · mantisbt21 Eyl 2011
- CVE-2020-3584930İzleyin
An issue was discovered in MantisBT before 2.24.4.
YüksekCVSS 7,5İstismar yokEPSS %2mantisbt · mantisbt30 Ara 2020
- CVE-2025-4655630İzleyin
MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length
YüksekCVSS 7,5İstismar yokEPSS %0mantisbt · mantisbt3 Kas 2025