vciy

CVEs we hold for Mantisbt

Records whose assigning authority named Mantisbt as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-47156MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administratormantisbt
CVE-2026-44657MantisBT: Stored XSS in File Downloadmantisbt
CVE-2026-44655MantisBT: Stored XSS on Move Attachments Admin Pagemantisbt
CVE-2026-42071MantisBT: Private Bugnote Attachment Content Leak via REST APImantisbt
CVE-2026-42070MantisBT: Authorization Bypass in Bugnote Editing via Issue Update APImantisbt
CVE-2026-41897MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Fieldmantisbt
CVE-2026-40607MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Columnmantisbt
CVE-2026-40598MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Pagemantisbt
CVE-2026-40597MantisBT has a Content Security Policy bypass via attachmentsmantisbt
CVE-2026-40596MantisBT is vulnerable to XSS and potential account takeover via user font family preference updatemantisbt
CVE-2026-39960MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Valuesmantisbt
CVE-2026-34970MantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revokedmantisbt
CVE-2026-34754MantisBT allows unauthorized users to upload attachments to restricted issues via REST APImantisbt
CVE-2026-34744MantisBT authorization bypass allows continued access to self-uploaded attachments on private issuesmantisbt
CVE-2026-34579MantisBT has an authorization bypass via private issue monitoringmantisbt
CVE-2026-34463MantisBT has Stored HTML Injection/XSS via Clone Issue Formmantisbt
CVE-2026-34390MantisBT: Privilege Escalation from Manager to Administratormantisbt
CVE-2026-33548MantisBT has Stored HTML Injection / XSS when displaying Tags in Timelinemantisbt
CVE-2026-33517MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmationmantisbt
CVE-2026-33052MantisBT: Authorization Bypass in Global Profile Creationmantisbt
CVE-2026-30849MantisBT SOAP API has an authentication bypass vulnerability on MySQLmantisbt
CVE-2025-62520MantisBT unauthorized disclosure of private project column configurationmantisbt
CVE-2025-55155MantisBT: Authentication bypass for some passwords due to PHP type jugglingmantisbt
CVE-2025-47776MantisBT: Authentication bypass for some passwords due to PHP type jugglingmantisbt
CVE-2025-46556MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Lengthmantisbt
CVE-2024-45792MantisBT vulnerable to information disclosure with user profilesmantisbt
CVE-2024-34081MantisBT Cross-site Scripting vulnerabilitymantisbt
CVE-2024-34080MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actormantisbt
CVE-2024-34077MantisBT user account takeover in the signup/reset password processmantisbt
CVE-2024-23830MantisBT Host Header Injection vulnerabilitymantisbt
CVE-2023-49802MantisBT LinkedCustomFields Cross-site Scripting vulnerabilitymantisbt-plugins LinkedCustomFields
CVE-2023-44394Disclosure of project names to unauthorized users in MantisBTmantisbt
CVE-2023-22476MantisBT: Exposure of Private issues' summary to unauthorized usersmantisbt
CVE-2013-1934no title heldmantisBT
CVE-2013-1932no title heldmantisBT
CVE-2013-1931no title heldmantisBT
CVE-2013-1930no title heldmantisBT

37 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.