mantisbt/mantisbt vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-62944Highmantisbt/mantisbt: MantisBT: Stored XSS in print_all_bug_page_word.phpCVE-2026-52883Mediummantisbt/mantisbt: MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIsCVE-2026-52882Mediummantisbt/mantisbt: MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From UpdatersCVE-2026-52881Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.php via unescaped printf CVE-2026-52847Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.phpCVE-2026-49280Mediummantisbt/mantisbt: MantisBT: REST API unauthorized Issue status changeCVE-2026-49273Highmantisbt/mantisbt: MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.phpCVE-2026-47156Criticalmantisbt/mantisbt: MantisBT: SOAP API Authentication Bypass with Privilege Escalation to AdministratorCVE-2026-47142Highmantisbt/mantisbt: MantisBT: SQL Injection via history_order Configuration ValueCVE-2026-44657Highmantisbt/mantisbt: MantisBT Vulnerable to Stored XSS in File DownloadCVE-2026-44655Highmantisbt/mantisbt: MantisBT has Stored XSS on Move Attachments Admin PageCVE-2026-42071Highmantisbt/mantisbt: MantisBT has a Private Bugnote Attachment Content Leak via REST APICVE-2026-42070Mediummantisbt/mantisbt: MantisBT: Authorization Bypass in Bugnote Editing via Issue Update APICVE-2026-41897Mediummantisbt/mantisbt: MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea FieldCVE-2026-40607Highmantisbt/mantisbt: MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner ColumnCVE-2026-40598Mediummantisbt/mantisbt: MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update PageCVE-2026-40597Highmantisbt/mantisbt: MantisBT has a Content Security Policy bypass via attachmentsCVE-2026-40596Highmantisbt/mantisbt: MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preferenceCVE-2026-39960Mediummantisbt/mantisbt: MantisBT is Vulnerable to Stored XSS in Custom Field Textarea ValuesCVE-2026-34970Mediummantisbt/mantisbt: MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is RevokedCVE-2026-34754Mediummantisbt/mantisbt: MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST APICVE-2026-34744Mediummantisbt/mantisbt: MantisBT has an authorization bypass that allows reading attachments after losing access to a private issueCVE-2026-34579Mediummantisbt/mantisbt: MantisBT has an authorization bypass in private issue monitoringCVE-2026-34463Highmantisbt/mantisbt: MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue FormCVE-2026-34390Mediummantisbt/mantisbt: MantisBT Vulnerable to Privilege Escalation from Manager to Administrator

Stop the waste.
Protect your environment with Kodem.