CVEs we hold for Mantisbt
Records whose assigning authority named Mantisbt as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-47156MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administratormantisbt CVE-2026-44655MantisBT: Stored XSS on Move Attachments Admin Pagemantisbt CVE-2026-42071MantisBT: Private Bugnote Attachment Content Leak via REST APImantisbt CVE-2026-42070MantisBT: Authorization Bypass in Bugnote Editing via Issue Update APImantisbt CVE-2026-41897MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Fieldmantisbt CVE-2026-40607MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Columnmantisbt CVE-2026-40598MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Pagemantisbt CVE-2026-40597MantisBT has a Content Security Policy bypass via attachmentsmantisbt CVE-2026-40596MantisBT is vulnerable to XSS and potential account takeover via user font family preference updatemantisbt CVE-2026-39960MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Valuesmantisbt CVE-2026-34970MantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revokedmantisbt CVE-2026-34754MantisBT allows unauthorized users to upload attachments to restricted issues via REST APImantisbt CVE-2026-34744MantisBT authorization bypass allows continued access to self-uploaded attachments on private issuesmantisbt CVE-2026-34579MantisBT has an authorization bypass via private issue monitoringmantisbt CVE-2026-34463MantisBT has Stored HTML Injection/XSS via Clone Issue Formmantisbt CVE-2026-34390MantisBT: Privilege Escalation from Manager to Administratormantisbt CVE-2026-33548MantisBT has Stored HTML Injection / XSS when displaying Tags in Timelinemantisbt CVE-2026-33517MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmationmantisbt CVE-2026-33052MantisBT: Authorization Bypass in Global Profile Creationmantisbt CVE-2026-30849MantisBT SOAP API has an authentication bypass vulnerability on MySQLmantisbt CVE-2025-62520MantisBT unauthorized disclosure of private project column configurationmantisbt CVE-2025-55155MantisBT: Authentication bypass for some passwords due to PHP type jugglingmantisbt CVE-2025-47776MantisBT: Authentication bypass for some passwords due to PHP type jugglingmantisbt CVE-2025-46556MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Lengthmantisbt CVE-2024-45792MantisBT vulnerable to information disclosure with user profilesmantisbt CVE-2024-34080MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actormantisbt CVE-2024-34077MantisBT user account takeover in the signup/reset password processmantisbt CVE-2023-49802MantisBT LinkedCustomFields Cross-site Scripting vulnerabilitymantisbt-plugins LinkedCustomFields CVE-2023-44394Disclosure of project names to unauthorized users in MantisBTmantisbt CVE-2023-22476MantisBT: Exposure of Private issues' summary to unauthorized usersmantisbt 37 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.