📦 Mantisbt

by Mantisbt

🔍 What is Mantisbt?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-34077

HIGH CVSS 7.3 May 14, 2024

MantisBT versions before 2.26.2 have an insufficient access control vulnerability in the registration and password reset process. An attacker can reset another user's password and take over their acco...

CVE-2024-23830

HIGH CVSS 8.3 Feb 20, 2024

CVE-2024-23830 is an account hijack vulnerability in MantisBT where an unauthenticated attacker can take over user accounts by poisoning password reset links. This affects all MantisBT instances prior...

CVE-2025-46556

MEDIUM CVSS 6.5 Nov 4, 2025

Mantis Bug Tracker versions 2.27.1 and below are vulnerable to a denial-of-service attack where attackers can submit extremely long notes (over 4.7 million characters) that permanently corrupt issue a...

CVE-2024-45792

MEDIUM CVSS 6.5 Sep 30, 2024

An information disclosure vulnerability in Mantis Bug Tracker allows unprivileged registered users to retrieve other users' personal system profile information via crafted POST requests. This affects ...

CVE-2024-34080

MEDIUM CVSS 5.3 May 14, 2024

MantisBT versions before 2.26.2 have an information disclosure vulnerability where users can see metadata about notes they shouldn't have access to. When an issue references a note from another restri...