Vulnerabilities in mantisbt
35 resultsVexday analysis
O Mantis BT possui 31 CVEs registradas, com concentração preocupante de 17 divulgações nos últimos 90 dias, indicando descobertas recentes de vulnerabilidades. A fraqueza dominante é XSS (CWE-79), típica de aplicações web, embora nenhuma esteja sob exploração ativa conhecida e apenas 1 vulnerabilidade atinja nível crítico. O padrão de descobertas recentes sugere revisão contínua do código, exigindo monitoramento atento das patches.
CVE-2026-34579MEDIUMMantisBT has an authorization bypass via private issue monitoringEPSS 0.4%CVE-2026-34744MEDIUMMantisBT authorization bypass allows continued access to self-uploaded attachments on private issuesEPSS 0.4%CVE-2026-44657HIGHMantisBT: Stored XSS in File DownloadEPSS 0.3%CVE-2026-33052MEDIUMMantisBT: Authorization Bypass in Global Profile CreationEPSS 0.3%CVE-2025-47776HIGHMantisBT: Authentication bypass for some passwords due to PHP type jugglingEPSS 0.3%CVE-2026-44655HIGHMantisBT: Stored XSS on Move Attachments Admin PageEPSS 0.3%CVE-2026-41897MEDIUMMantisBT: Reflected XSS in Rendering Dynamic Custom Textarea FieldEPSS 0.3%CVE-2026-42071HIGHMantisBT: Private Bugnote Attachment Content Leak via REST APIEPSS 0.3%CVE-2026-42070MEDIUMMantisBT: Authorization Bypass in Bugnote Editing via Issue Update APIEPSS 0.3%CVE-2026-34754MEDIUMMantisBT allows unauthorized users to upload attachments to restricted issues via REST APIEPSS 0.2%CVE-2025-62520MEDIUMMantisBT unauthorized disclosure of private project column configurationEPSS 0.2%CVE-2026-33517HIGHMantisBT Vulnerable to Stored HTML Injection in Tag Delete ConfirmationEPSS 0.2%CVE-2026-39960MEDIUMMantisBT is Vulnerable to Stored XSS through Custom Field Textarea ValuesEPSS 0.2%CVE-2026-33548HIGHMantisBT has Stored HTML Injection / XSS when displaying Tags in TimelineEPSS 0.2%CVE-2025-55155MEDIUMMantisBT: Authentication bypass for some passwords due to PHP type jugglingEPSS 0.2%