Security Advisories for mantisbt/mantisbt in packagist
Moderate
1 day ago
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
packagist
mantisbt/mantisbt
Moderate
1 day ago
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
packagist
mantisbt/mantisbt
Critical
1 day ago
MantisBT: Reflected XSS in admin/install.php via unescaped printf
packagist
mantisbt/mantisbt
High
1 day ago
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
packagist
mantisbt/mantisbt
Critical
1 day ago
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
packagist
mantisbt/mantisbt
High
1 day ago
MantisBT: SQL Injection via history_order Configuration Value
packagist
mantisbt/mantisbt
High
2 months ago
MantisBT has Stored XSS on Move Attachments Admin Page
packagist
mantisbt/mantisbt
High
2 months ago
MantisBT has a Private Bugnote Attachment Content Leak via REST API
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea Field
packagist
mantisbt/mantisbt
High
2 months ago
MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page
packagist
mantisbt/mantisbt
High
2 months ago
MantisBT has a Content Security Policy bypass via attachments
packagist
mantisbt/mantisbt
High
2 months ago
MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT is Vulnerable to Stored XSS in Custom Field Textarea Values
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT has an authorization bypass in private issue monitoring
packagist
mantisbt/mantisbt
High
2 months ago
MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT Vulnerable to Privilege Escalation from Manager to Administrator
packagist
mantisbt/mantisbt
Moderate
2 months ago
MantisBT Has Authorization Bypass in Global Profile Creation
packagist
mantisbt/mantisbt
High
4 months ago
MantisBT has Stored HTML Injection/XSS when displaying Tags in Timeline
packagist
mantisbt/mantisbt
High
4 months ago
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
packagist
mantisbt/mantisbt
Critical
4 months ago
MantisBT is vulnerable to authentication bypass through the SOAP API on MySQL
packagist
mantisbt/mantisbt
Moderate
8 months ago
MantisBT unauthorized disclosure of private project column configuration
packagist
mantisbt/mantisbt
Moderate
8 months ago
MantisBT lacks verification when changing a user's email address
packagist
mantisbt/mantisbt
Moderate
9 months ago
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
packagist
mantisbt/mantisbt
High
9 months ago
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
packagist
mantisbt/mantisbt
Moderate
almost 2 years ago
MantisBT vulnerable to information disclosure with user profiles
packagist
mantisbt/mantisbt
Moderate
about 2 years ago
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting
packagist
mantisbt/mantisbt
Moderate
about 2 years ago
MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
packagist
mantisbt/mantisbt
High
about 2 years ago
Mantis Bug Tracker (MantisBT) allows user account takeover in the signup/reset password process
packagist
mantisbt/mantisbt
Moderate
over 2 years ago
MantisBT may disclose project names to unauthorized users
packagist
mantisbt/mantisbt
Moderate
over 3 years ago
MantisBT may expose private issues' summaries to unauthorized users
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XSS through crafted SVG documents in file_download.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT allows XSS in manage_custom_field_edit_page.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XSS in manage_custom_field_update.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT Incorrect Authorization in bug_actiongroup_page.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT Missing Authorization access check in bug_actiongroup.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT Insecure Storage in manage_proj_edit_page.php
packagist
mantisbt/mantisbt
High
about 4 years ago
MantisBT Incorrect Authorization for bug_revision_view_page.php check
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT SQL Injection via mc_project_get_users function
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT unauthorized users able to access private files
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XXS where a Custom Field with a crafted Regular Expression property is used
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XSS issue on the view_all_bug_page.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT allows cross-site scripting (XSS) via crafted filename
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT cross-site scripting (XSS) vulnerability through crafted PATH_INFO
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XSS through weak CSP when using Gravatar plugin
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT vulnerable to CSRF and Open Redirect attacks
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XSS via my_view_page.php and view_user_page.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XSS via adm_config_report.php's action parameter
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT vulnerable to XSS through config_option parameter in adm_config_report.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT allows XSS on the Edit Filter page via crafted filter name
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT allows XSS via the Manage Filter page
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT XSS allows unsanitized input via admin/install.php
packagist
mantisbt/mantisbt
Moderate
about 4 years ago
MantisBT vulnerable to XSS via unescaped output in browser_search_plugin.php
packagist
mantisbt/mantisbt
High
about 4 years ago
MantisBT Insufficient Session Expiration cookie string not reset after logout
packagist
mantisbt/mantisbt
High
over 4 years ago
MantisBT CSV Injection unprivileged user access in csv_export.php
packagist
mantisbt/mantisbt
Moderate
over 4 years ago
MantisBT vulnerable to XSS due to improper escape in manage_plugin_page.php and manage_plugin_uninstall.php
packagist
mantisbt/mantisbt