Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-47156
  • github.com/mantisbt/mantisbt
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 09 Sep
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-h2wf-967x-gxvw
  • Packagist/mantisbt/mantisbt
MantisBT: Stored XSS in print_all_bug_page_word.php 15 Jul
  • Fix available
  • Severity - 8.6 (High)
GHSA-4vpf-w7qv-5h3q
  • Packagist/mantisbt/mantisbt
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs 15 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-3v2j-6fw9-f57c
  • Packagist/mantisbt/mantisbt
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters 15 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-vcrw-4xvv-jh49
  • Packagist/mantisbt/mantisbt
MantisBT: Reflected XSS in admin/install.php via unescaped printf 15 Jul
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-77x8-3v3h-hrhv
  • Packagist/mantisbt/mantisbt
MantisBT: Reflected XSS in admin/install.php 15 Jul
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-m7ph-9558-mrx3
  • Packagist/mantisbt/mantisbt
MantisBT: REST API unauthorized Issue status change 15 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-v84x-qvhg-f36r
  • Packagist/mantisbt/mantisbt
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php 15 Jul
  • Fix available
  • Severity - 8.6 (High)
GHSA-c2xg-qjqw-2v98
  • Packagist/mantisbt/mantisbt
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 15 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-mw6p-33vw-46cc
  • Packagist/mantisbt/mantisbt
MantisBT: SQL Injection via history_order Configuration Value 15 Jul
  • Fix available
  • Severity - 8.5 (High)
CVE-2026-42071
  • github.com/mantisbt/mantisbt
MantisBT: Private Bugnote Attachment Content Leak via REST API 28 May
  • Fix available
  • Severity - 7.2 (High)
CVE-2026-42070
  • github.com/mantisbt/mantisbt
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API 28 May
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-44655
  • github.com/mantisbt/mantisbt
MantisBT: Stored XSS on Move Attachments Admin Page 28 May
  • Fix available
  • Severity - 8.6 (High)
CVE-2026-41897
  • github.com/mantisbt/mantisbt
MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Field 28 May
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-44657
  • github.com/mantisbt/mantisbt
MantisBT: Stored XSS in File Download 28 May
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-40607
  • github.com/mantisbt/mantisbt
MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column 22 May
  • Fix available
  • Severity - 7.5 (High)